漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Bulwark Webmail getClientIP() trusted client-controlled X-Forwarded-For value, enabling rate limit bypass and audit log forgery
Vulnerability Description
Bulwark Webmail is a self-hosted webmail client for Stalwart Mail Server. Prior to 1.4.11, the getClientIP() function in lib/admin/session.ts trusted the first (leftmost) entry of the X-Forwarded-For header, which is fully controlled by the client. An attacker could forge their source IP address to bypass IP-based rate limiting (enabling brute-force attacks against the admin login) or forge audit log entries (making malicious activity appear to originate from arbitrary IP addresses). This vulnerability is fixed in 1.4.11.
CVSS Information
N/A
Vulnerability Type
使用不可信的源
Vulnerability Title
Bulwark Webmail 安全漏洞
Vulnerability Description
Bulwark Webmail是Bulwark Mail开源的一个自托管网页邮件客户端。 Bulwark Webmail 1.4.11之前版本存在安全漏洞,该漏洞源于getClientIP函数信任客户端可控的X-Forwarded-For标头,可能导致绕过基于IP的速率限制或伪造审计日志。
CVSS Information
N/A
Vulnerability Type
N/A