Back

HIGH

mod_wsgi: Trusted Proxy Headers Removing Bypass

Published Aug 25, 2022

Description

A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 25, 2022
Updated Aug 3, 2024
Reserved Jun 29, 2022
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 18, 2022
GHSA-7527-8855-9CF8