漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Possibilities of IP Spoofing via X-Forwarded-For (XFF) Header
Vulnerability Description
In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header. Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized access if the spoofed IP matched a whitelisted range. This vulnerability could be exploited to bypass IP restrictions, though valid user credentials would still be required for resource access.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
Progress Hybrid Data Pipeline Server 安全漏洞
Vulnerability Description
Progress Hybrid Data Pipeline Server是美国Progress公司的一个数据管道服务器。 Progress Hybrid Data Pipeline Server 4.6.2.2978之前版本存在安全漏洞,该漏洞源于X-Forwarded-For标头可能被伪造,可能导致未授权访问。
CVSS Information
N/A
Vulnerability Type
N/A