PT-2024-36336 · Kurmi · Kurmi Provisioning Suite

Published

2024-12-27

·

Updated

2024-12-28

·

CVE-2024-54450

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Kurmi Provisioning Suite version 7.9.0.33
Description: An issue was discovered in the Kurmi Provisioning Suite. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the possibly forged IP address mentioned in that header rather than the real IP address that the user logged in from. This fake IP address can later be displayed in the My Account popup that shows the IP address that was used to log in.
Recommendations: For Kurmi Provisioning Suite version 7.9.0.33, as a temporary workaround, consider disabling the use of the X-Forwarded-For header during authentication until a patch is available. Restrict access to the My Account popup to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2024-54450

Affected Products

Kurmi Provisioning Suite