VDB
Sign up
HIGH7.0

GHSA-ghw3-5qvm-3mqc

CodeIgniter4 allows spoofing of IP address when using proxy

Quick fix

GHSA-ghw3-5qvm-3mqc — codeigniter4/framework: upgrade to the fixed version with the command below.

composer require codeigniter4/framework:^4.2.11

Details

### Impact This vulnerability may allow attackers to spoof their IP address when your server is behind a reverse proxy.

### Patches Upgrade to v4.2.11 or later, and configure `Config\App::$proxyIPs`.

### Workarounds Do not use `$request->getIPAddress()`.

### References - https://codeigniter4.github.io/userguide/incoming/request.html#CodeIgniter\HTTP\Request::getIPAddress

### For more information If you have any questions or comments about this advisory: * Open an issue in [codeigniter4/CodeIgniter4](https://github.com/codeigniter4/CodeIgniter4/issues) * Email us at [SECURITY.md](https://github.com/codeigniter4/CodeIgniter4/blob/develop/SECURITY.md)

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/codeigniter4/framework
Introduced in: 0Fixed in: 4.2.11
Fixcomposer require codeigniter4/framework:^4.2.11

References