PT-2024-40527 · Zend · Zendhttpphpenvironmentremoteaddress

Published

2024-06-07

·

Updated

2024-06-07

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: ZendHttpPhpEnvironmentRemoteAddress versions prior to 2.2.5
Description: The issue concerns the detection of the internet protocol (IP) address for an incoming proxied request via the X-Forwarded-For header. The class did not properly consider whether the IP address in PHP's $ SERVER['REMOTE ADDR'] was in the list of trusted proxy server IPs. According to the IETF draft specification, if $ SERVER['REMOTE ADDR'] is not a trusted proxy, it should be considered the originating IP address, and the X-Forwarded-For value should be disregarded.
Recommendations: For versions prior to 2.2.5, update to version 2.2.5 or later to resolve the issue.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-XFFP-6W68-4775

Affected Products

Zendhttpphpenvironmentremoteaddress