{"id":"GHSA-ffp2-8p2h-4m5j","summary":"Password Pusher rate limiter can be bypassed by forging proxy headers","details":"### Impact\n\nPassword Pusher comes with a configurable rate limiter.  In versions prior to [v1.49.0](https://github.com/pglombardo/PasswordPusher/releases/tag/v1.49.0), the rate limiter could be bypassed by forging proxy headers allowing bad actors to send unlimited traffic to the site potentially causing a denial of service.\n\nAdditionally, with the ability to bypass rate limiting, it also allows attackers to more easily execute brute force attacks.\n\n### Patches\n\nIn [v1.49.0](https://github.com/pglombardo/PasswordPusher/releases/tag/v1.49.0), a fix was implemented to only authorize proxies on local IPs which resolves this issue.\n\nIf you are running a remote proxy, please see [this documentation](https://docs.pwpush.com/docs/proxies/#trusted-proxies) on how to authorize the IP address of your remote proxy.\n\n### Workarounds\n\nIt is highly suggested to upgrade to at least [v1.49.0](https://github.com/pglombardo/PasswordPusher/releases/tag/v1.49.0) to mitigate this risk.\n\nIf for some reason you cannot immediately upgrade, the alternative is that you can add rules to your proxy and/or firewall to not accept external proxy headers such as `X-Forwarded-*` from clients.\n\n### References\n\nThe new settings are [configurable to authorize remote proxies](https://docs.pwpush.com/docs/proxies/#trusted-proxies).\n\n### Credits\n\nThank you to [Positive Technologies](https://www.ptsecurity.com/ww-en/) for reporting and working with me to bring this CVE to the community with the associated fix.\n","aliases":["CVE-2024-52796"],"modified":"2024-11-26T19:08:23.465443Z","published":"2024-11-20T18:24:28Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-11-20T18:24:28Z","nvd_published_at":"2024-11-20T17:15:20Z","cwe_ids":["CWE-770"],"severity":"LOW"},"references":[{"type":"WEB","url":"https://github.com/pglombardo/PasswordPusher/security/advisories/GHSA-ffp2-8p2h-4m5j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52796"},{"type":"WEB","url":"https://docs.pwpush.com/docs/proxies/#trusted-proxies"},{"type":"PACKAGE","url":"https://github.com/pglombardo/PasswordPusher"},{"type":"WEB","url":"https://github.com/pglombardo/PasswordPusher/releases/tag/v1.49.0"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/pwpush/CVE-2024-52796.yml"}],"affected":[{"package":{"name":"pwpush","ecosystem":"RubyGems","purl":"pkg:gem/pwpush"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.49.0"}]}],"versions":["0.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-ffp2-8p2h-4m5j/GHSA-ffp2-8p2h-4m5j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U"}]}