Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
High severity
GitHub Reviewed
Published
Jun 23, 2021
to the GitHub Advisory Database
•
Updated May 20, 2024
Description
Published by the National Vulnerability Database
Jan 20, 2021
Reviewed
May 12, 2021
Published to the GitHub Advisory Database
Jun 23, 2021
Last updated
May 20, 2024
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7.
References