216.73.216.6

CVE-2024-54450

· Published 27/12/2024 20:15 · Modified 28/12/2024 19:15

Labels: CVE-2024-54450 2024-12-27CVE-2024-54450CWE-290[email protected]

Essential information

Published
27/12/2024 20:15
Modified
28/12/2024 19:15
Author
Creator
CVSS
9.4 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H

CVSS metrics

Description

An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is received during authentication, the Kurmi application will record the (possibly forged) IP address mentioned in that header rather than the real IP address that the user logged in from. This fake IP address can later be displayed in the My Account popup that shows the IP address that was used to log in.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References