PT-2026-5492 · Unknown · Crystal Shard Http-Protection

Halis Duraki

·

Publicado

2026-01-30

·

Atualizado

2026-01-31

·

CVE-2020-37056

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Crystal Shard http-protection version 0.2.0
Description The software contains an IP spoofing issue that allows attackers to bypass protection middleware. This is achieved by manipulating request headers to hardcode consistent IP values across the X-Forwarded-For, X-Client-IP, and X-Real-IP headers, circumventing security checks and potentially gaining unauthorized access.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Correção

Authentication Bypass by Spoofing

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2020-37056

Produtos afetados

Crystal Shard Http-Protection