Candidate: CVE-2016-4793 PublicDate: 2017-01-23 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4793 http://legalhackers.com/advisories/CakePHP-IP-Spoofing-Vulnerability.txt https://bakery.cakephp.org/2016/03/13/cakephp_2613_2711_282_3017_3112_325_released.html https://www.exploit-db.com/exploits/39813/ Description: The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Dawid Golunski Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_cakephp: upstream_cakephp: released (2.8.2, 3.2.5) precise_cakephp: ignored (reached end-of-life) precise/esm_cakephp: DNE (precise was needs-triage) trusty_cakephp: released (1.3.15-1+deb7u2build0.14.04.1) trusty/esm_cakephp: DNE (trusty was released [1.3.15-1+deb7u2build0.14.04.1]) vivid/stable-phone-overlay_cakephp: DNE vivid/ubuntu-core_cakephp: DNE xenial_cakephp: ignored (end of standard support, was needed) yakkety_cakephp: not-affected (2.8.5-1) zesty_cakephp: not-affected artful_cakephp: not-affected bionic_cakephp: DNE cosmic_cakephp: not-affected disco_cakephp: not-affected eoan_cakephp: not-affected focal_cakephp: not-affected groovy_cakephp: not-affected hirsute_cakephp: not-affected impish_cakephp: not-affected jammy_cakephp: not-affected devel_cakephp: not-affected