VDB
Sign up
HIGH7.1

GHSA-h395-qcrw-5vmq

Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin

Quick fix

GHSA-h395-qcrw-5vmq — github.com/gin-gonic/gin: upgrade to the fixed version with the command below.

go get github.com/gin-gonic/gin@v1.7.7

Details

When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/gin-gonic/gin
Introduced in: 0Fixed in: 1.7.7
Fixgo get github.com/gin-gonic/gin@v1.7.7

References