VDB
Sign up
—

GO-2023-2394

Spoofed source IP address in github.com/shift72/caddy-geo-ip

Details

The caddy-geo-ip (aka GeoIP) middleware for Caddy 2 allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP address range restrictions).

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/shift72/caddy-geo-ip
Introduced in: 0

No fixed version published yet for github.com/shift72/caddy-geo-ip (go modules). Pin to a known-safe version or switch to an alternative.

References