CRITICAL9.1
GHSA-wxvr-qqm7-6h65
Knock Knock plugin IP Whitelist bypass via an X-Forwarded-For HTTP header
Quick fix
GHSA-wxvr-qqm7-6h65 — verbb/knock-knock: upgrade to the fixed version with the command below.
composer require verbb/knock-knock:^1.2.8Details
The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/verbb/knock-knock
Introduced in:
0Fixed in: 1.2.8Fix
composer require verbb/knock-knock:^1.2.8