Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWgzOTUtcWNydy01dm1x
Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin
When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7.
Permalink: https://github.com/advisories/GHSA-h395-qcrw-5vmqJSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWgzOTUtcWNydy01dm1x
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 3 years ago
Updated: 9 months ago
CVSS Score: 7.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Identifiers: GHSA-h395-qcrw-5vmq, CVE-2020-28483
References:
- https://nvd.nist.gov/vuln/detail/CVE-2020-28483
- https://github.com/gin-gonic/gin/pull/2632
- https://github.com/gin-gonic/gin/commit/bfc8ca285eb46dad60e037d57c545cd260636711
- https://github.com/gin-gonic/gin/releases/tag/v1.7.0
- https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGINGONICGIN-1041736
- https://github.com/gin-gonic/gin/issues/2232
- https://github.com/gin-gonic/gin/issues/2473
- https://github.com/gin-gonic/gin/issues/2862
- https://github.com/gin-gonic/gin/pull/2474#23issuecomment-729696437
- https://github.com/gin-gonic/gin/pull/2675
- https://github.com/gin-gonic/gin/pull/2844
- https://github.com/gin-gonic/gin/commit/03e5e05ae089bc989f1ca41841f05504d29e3fd9
- https://github.com/gin-gonic/gin/commit/5929d521715610c9dd14898ebbe1d188d5de8937
- https://github.com/gin-gonic/gin/releases/tag/v1.7.7
- https://pkg.go.dev/vuln/GO-2021-0052
- https://github.com/gin-gonic/gin/pull/2844/files#diff-e6ce689a25eaef174c2dd51fe869fabbe04a6c6afbd416b23eda138c82e761baR1432
- https://github.com/advisories/GHSA-h395-qcrw-5vmq
Blast Radius: 33.7
Affected Packages
go:github.com/gin-gonic/gin
Dependent packages: 23,911Dependent repositories: 55,159
Downloads:
Affected Version Ranges: < 1.7.7
Fixed in: 1.7.7
All affected versions: 1.1.1, 1.1.2, 1.1.3, 1.1.4, 1.3.0, 1.4.0, 1.5.0, 1.6.0, 1.6.1, 1.6.2, 1.6.3, 1.7.0, 1.7.1, 1.7.2, 1.7.3, 1.7.4, 1.7.5, 1.7.6
All unaffected versions: 1.7.7, 1.8.0, 1.8.1, 1.8.2, 1.9.0, 1.9.1