{"id":"BIT-codeigniter-2022-23556","details":"CodeIgniter is a PHP full-stack web framework. This vulnerability may allow attackers to spoof their IP address when the server is behind a reverse proxy. This issue has been patched, please upgrade to version 4.2.11 or later, and configure `Config\\App::$proxyIPs`. As a workaround, do not use `$request-\u003egetIPAddress()`.","aliases":["CVE-2022-23556","GHSA-ghw3-5qvm-3mqc"],"modified":"2024-03-06T11:25:28.861Z","published":"2024-03-06T10:54:16.602Z","database_specific":{"cpes":["cpe:2.3:a:codeigniter:codeigniter:*:*:*:*:*:*:*:*"],"severity":"High"},"references":[{"type":"WEB","url":"https://github.com/codeigniter4/CodeIgniter4/commit/5ca8c99b2db09a2a08a013836628028ddc984659"},{"type":"WEB","url":"https://github.com/codeigniter4/CodeIgniter4/security/advisories/GHSA-ghw3-5qvm-3mqc"}],"affected":[{"package":{"name":"codeigniter","ecosystem":"Bitnami","purl":"pkg:bitnami/codeigniter"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.2.11"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/codeigniter/BIT-codeigniter-2022-23556.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}],"schema_version":"1.7.3"}