VDB
Sign up
—

PYSEC-2022-254

Quick fix

PYSEC-2022-254 — mod-wsgi: upgrade to the fixed version with the command below.

pip install --upgrade 'mod-wsgi>=4.9.3'

Details

A vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/mod-wsgi
Introduced in: 0Fixed in: 4.9.3
Fixpip install --upgrade 'mod-wsgi>=4.9.3'

References