PT-2023-27914 · Gofiber · Gofiber

Schicho

·

Published

2023-09-08

·

Updated

2023-09-12

·

CVE-2023-41338

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions gofiber versions prior to 2.49.2
Description The issue impacts users who rely on the ctx.IsFromLocal method to restrict access to localhost requests. If exploited, it could allow unauthorized access to resources intended only for localhost. Setting X-Forwarded-For: 127.0.0.1 in a request from a foreign host will result in true for ctx.IsFromLocal. Access is limited to the scope of the affected process.
Recommendations To resolve the issue, upgrade to version 2.49.2 or later, as this issue has been patched in version 2.49.2 with commit b8c9ede6. As a temporary workaround, consider restricting the use of the ctx.IsFromLocal method until a patch is available. Avoid using the X-Forwarded-For header in requests to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-41338
GHSA-3Q5P-3558-364F
GO-2023-2052

Affected Products

Gofiber