—
GO-2023-2394
Spoofed source IP address in github.com/shift72/caddy-geo-ip
Details
The caddy-geo-ip (aka GeoIP) middleware for Caddy 2 allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP address range restrictions).
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/shift72/caddy-geo-ip
Introduced in:
0No fixed version published yet for github.com/shift72/caddy-geo-ip (go modules). Pin to a known-safe version or switch to an alternative.