漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header
Vulnerability Description
Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers can append attacker-controlled values to the header chain using the $proxy_add_x_forwarded_for directive to present an arbitrary IP address, circumventing Ghost's rate-limiting mechanisms on self-hosted instances.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
使用不可信的源
Vulnerability Title
Ghost-CLI 信任管理问题漏洞
Vulnerability Description
Ghost Ghost-CLI是Ghost组织的一款博客平台命令行管理工具。 Ghost-CLI 1.30.1之前版本存在信任管理问题漏洞,该漏洞源于通过错误配置的Nginx配置中的$proxy_add_x_forwarded_for指令操纵X-Forwarded-For标头,可能允许未经身份验证的远程攻击者绕过速率限制。
CVSS Information
N/A
Vulnerability Type
N/A