5.3

CVE-2023-44463

An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to trust unchecked X-Forwarded-For headers even though it has not been configured to do so. This can lead to IP address spoofing by users of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RamiPretix Version < 2023.7.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.396
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-290 Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

https://github.com/pretix/pretix/tags
Release Notes
https://pretix.eu/about/en/ticketing
Product
https://github.com/pretix/pretix/commit/ccdce2ccb8207b82501af3c03f50abc0f819b469
Patch
https://github.com/pretix/pretix/compare/v2023.7.0...v2023.7.1
Patch
https://pretix.eu/about/en/blog/20230911-release-2023-7-1/
Release Notes