Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3353 | Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable rate limiter. In versions prior to v1.49.0, the rate limiter could be bypassed by forging proxy headers allowing bad actors to send unlimited traffic to the site potentially causing a denial of service. In v1.49.0, a fix was implemented to only authorize proxies on local IPs which resolves this issue. As a workaround, one may add rules to one's proxy and/or firewall to not accept external proxy headers such as `X-Forwarded-*` from clients. |
Github GHSA |
GHSA-ffp2-8p2h-4m5j | Password Pusher rate limiter can be bypassed by forging proxy headers |
Wed, 20 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pglombardo
Pglombardo password Pusher |
|
| CPEs | cpe:2.3:a:pglombardo:password_pusher:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pglombardo
Pglombardo password Pusher |
|
| Metrics |
ssvc
|
Wed, 20 Nov 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable rate limiter. In versions prior to v1.49.0, the rate limiter could be bypassed by forging proxy headers allowing bad actors to send unlimited traffic to the site potentially causing a denial of service. In v1.49.0, a fix was implemented to only authorize proxies on local IPs which resolves this issue. As a workaround, one may add rules to one's proxy and/or firewall to not accept external proxy headers such as `X-Forwarded-*` from clients. | |
| Title | Password Pusher's rate limiter can be bypassed by forging proxy headers | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-11-20T16:48:09.821Z
Reserved: 2024-11-15T17:11:13.439Z
Link: CVE-2024-52796
Updated: 2024-11-20T16:48:02.665Z
Status : Deferred
Published: 2024-11-20T17:15:20.953
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-52796
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA