Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2505 | Serilog before v2.1.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as a value of X-Forwarded-For or Client-Ip headers while performing HTTP requests. |
Github GHSA |
GHSA-5x5q-cqf6-gj8r | Serilog Client IP Spoofing vulnerability |
Wed, 04 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Serilog
Serilog serilog |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:serilog:serilog:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Serilog
Serilog serilog |
|
| Metrics |
ssvc
|
Wed, 04 Sep 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Serilog-contrib
Serilog-contrib serilog-enrichers-clientinfo |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:serilog-contrib:serilog-enrichers-clientinfo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Serilog-contrib
Serilog-contrib serilog-enrichers-clientinfo |
|
| Metrics |
cvssV3_1
|
Thu, 29 Aug 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Serilog before v2.1.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as a value of X-Forwarded-For or Client-Ip headers while performing HTTP requests. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-03-14T15:56:25.320Z
Reserved: 2024-08-21T00:00:00.000Z
Link: CVE-2024-44930
Updated: 2024-09-04T18:35:03.799Z
Status : Modified
Published: 2024-08-29T18:15:14.830
Modified: 2025-03-14T16:15:35.560
Link: CVE-2024-44930
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA