32 lines
1.3 KiB
JSON
Raw Normal View History

{
"id": "CVE-2024-34451",
"sourceIdentifier": "cve@mitre.org",
"published": "2024-06-16T22:15:09.130",
"lastModified": "2024-06-17T12:42:04.623",
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "Ghost through 5.85.1 allows remote attackers to bypass an authentication rate-limit protection mechanism by using many X-Forwarded-For headers with different values. NOTE: the vendor's position is that Ghost should be installed with a reverse proxy that allows only trusted X-Forwarded-For headers."
},
{
"lang": "es",
"value": "Ghost hasta 5.85.1 permite a atacantes remotos eludir un mecanismo de protecci\u00f3n de l\u00edmite de tasa de autenticaci\u00f3n mediante el uso de muchos encabezados X-Forwarded-For con diferentes valores. NOTA: la posici\u00f3n del proveedor es que Ghost debe instalarse con un proxy inverso que permita solo encabezados X-Forwarded-For confiables."
}
],
"metrics": {},
"references": [
{
"url": "https://docs.google.com/document/d/1iy0X4Vc9xXYoBxFrcW6ATo8GKPV6ivuLVzn6GgEpwqE",
"source": "cve@mitre.org"
},
{
"url": "https://ghost.org/docs/faq/proxying-https-infinite-loops/",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/TryGhost/Ghost/releases",
"source": "cve@mitre.org"
}
]
}