Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The org.eclipse.kura.web2 (Web Console) and org.eclipse.kura.rest.provider (REST API) components use this header as the primary IP source when initializing audit context, and org.eclipse.kura.jetty.customizer unconditionally installs Jetty's ForwardedRequestCustomizer on all HTTP/HTTPS connectors, causing HttpServletRequest.getRemoteAddr() to reflect the attacker-controlled header value. An unauthenticated remote attacker can exploit this vulnerability to bypass IP-based brute-force protections — such as fail2ban — by spoofing the logged IP address to a non-routable value, allowing a brute-force attack to proceed undetected, or to cause a denial of service against a third party by injecting a victim's IP address and triggering a ban on that address.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Vulnerability Type
使用不可信的源
Vulnerability Title
Eclipse kura 输入验证错误漏洞
Vulnerability Description
Eclipse kura是美国Eclipse基金会开源的一套物联网应用框架。 Eclipse kura 5.6.2之前版本存在安全漏洞,该漏洞源于信任客户端提供的X-Forwarded-For HTTP标头,可能导致未经身份验证的远程攻击者绕过基于IP的暴力破解保护,或者通过注入受害者IP地址导致对第三方拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A