6.5
CVSSv3

CVE-2023-50463

Published: 10/12/2023 Updated: 13/12/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The caddy-geo-ip (aka GeoIP) middleware up to and including 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows malicious users to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP address range restrictions).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

caddyserver caddy