PT-2024-26357 · Sshpiper · Sshpiper

Pgibson1-Godaddy

·

Published

2024-05-14

·

Updated

2024-07-08

·

CVE-2024-35175

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions sshpiper versions 1.0.50 through 1.2.x
Description The way the proxy protocol listener is implemented in sshpiper can allow an attacker to forge their connecting address. This means that any connection that sshpiper is directly or indirectly exposed to can use proxy protocol to forge its source address, potentially making logs less useful for whitelisting, rate limiting, or security investigations.
Recommendations For versions 1.0.50 through 1.2.x, upgrade to version 1.3.0 to patch the issue. As a temporary workaround, consider disabling the proxy protocol listener until a patch is available. Restrict access to sshpiper to minimize the risk of exploitation, ensuring it is only accessible in trusted environments.

Exploit

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

CVE-2024-35175
GHSA-4W53-6JVP-GG52
GO-2024-2853

Affected Products

Sshpiper