CVE-2015-3224

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
26/07/2015
Last modified:
03/12/2016

Description

request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rubyonrails:web_console:*:*:*:*:*:*:*:* 2.1.2 (including)