CVE-2022-2255

NameCVE-2022-2255
DescriptionA vulnerability was found in mod_wsgi. The X-Client-IP header is not removed from a request from an untrusted proxy, allowing an attacker to pass the X-Client-IP header to the target WSGI application because the condition to remove it is missing.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3111-1
Debian Bugs1016476

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mod-wsgi (PTS)buster4.6.5-1vulnerable
buster (security)4.6.5-1+deb10u1fixed
bullseye4.7.1-3+deb11u1fixed
bookworm4.9.4-1fixed
sid, trixie5.0.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mod-wsgisourcebuster4.6.5-1+deb10u1DLA-3111-1
mod-wsgisourcebullseye4.7.1-3+deb11u1
mod-wsgisource(unstable)4.9.0-1.11016476

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2100563
https://github.com/GrahamDumpleton/mod_wsgi/commit/af3c0c2736bc0b0b01fa0f0aad3c904b7fa9c751 (4.9.3)
WSGITrustedProxies and vulnerable code introduced in https://github.com/GrahamDumpleton/mod_wsgi/commit/543fc33c23b4cb5e623d574b7efbf85c8dedb396 (4.4.10)

Search for package or bug name: Reporting problems