CVE-2023-50463
The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP address range restrictions).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-50463?
CVE-2023-50463 has a high severity as it allows IP address spoofing, potentially bypassing access controls.
How do I fix CVE-2023-50463?
To fix CVE-2023-50463, upgrade the caddy-geo-ip middleware to version 0.6.1 or later.
What products are affected by CVE-2023-50463?
CVE-2023-50463 affects the caddy-geo-ip middleware up to version 0.6.0 and Caddy versions up to 2.0.
What type of attack does CVE-2023-50463 facilitate?
CVE-2023-50463 facilitates attacks that involve spoofing the source IP address using the X-Forwarded-For header.
What are the implications of CVE-2023-50463 for network security?
CVE-2023-50463 poses significant implications for network security as it can allow unauthorized access and impact trust in traffic originating from reverse proxies.