PT-2024-36336 · Kurmi · Kurmi Provisioning Suite
Published
2024-12-27
·
Updated
2024-12-28
·
CVE-2024-54450
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Kurmi Provisioning Suite version 7.9.0.33
Description:
An issue was discovered in the Kurmi Provisioning Suite. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the possibly forged IP address mentioned in that header rather than the real IP address that the user logged in from. This fake IP address can later be displayed in the My Account popup that shows the IP address that was used to log in.
Recommendations:
For Kurmi Provisioning Suite version 7.9.0.33, as a temporary workaround, consider disabling the use of the X-Forwarded-For header during authentication until a patch is available. Restrict access to the My Account popup to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kurmi Provisioning Suite