{"id":"GHSA-5x5q-cqf6-gj8r","summary":"Serilog Client IP Spoofing vulnerability","details":"Serilog (before v2.1.0) contains a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses in log files by specifying an arbitrary IP as a value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.\n\nIt is not possible to configure Serilog.Enrichers.ClientInfo to not trust the X-Forwarded-For header.","aliases":["CVE-2024-44930"],"modified":"2024-09-04T21:37:57.592830Z","published":"2024-08-29T18:31:36Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-08-29T21:07:16Z","nvd_published_at":"2024-08-29T18:15:14Z","cwe_ids":["CWE-348","CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-44930"},{"type":"WEB","url":"https://github.com/serilog-contrib/serilog-enrichers-clientinfo/issues/29"},{"type":"WEB","url":"https://github.com/serilog-contrib/serilog-enrichers-clientinfo/pull/38"},{"type":"WEB","url":"https://github.com/serilog-contrib/serilog-enrichers-clientinfo/commit/a72051d1900131e6fb30bcfd9491a988167fb6ac"},{"type":"PACKAGE","url":"https://github.com/serilog-contrib/serilog-enrichers-clientinfo"},{"type":"WEB","url":"https://github.com/serilog-contrib/serilog-enrichers-clientinfo/releases/tag/v2.1.0"}],"affected":[{"package":{"name":"Serilog.Enrichers.ClientInfo","ecosystem":"NuGet","purl":"pkg:nuget/Serilog.Enrichers.ClientInfo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0"}]}],"versions":["1.0.0","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.4-dev01","1.2.0","1.3.0","2.0.0","2.0.1","2.0.2","2.0.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-5x5q-cqf6-gj8r/GHSA-5x5q-cqf6-gj8r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}