#VU66201 Security features bypass in mod_wsgi - CVE-2022-2255
Published: August 9, 2022
mod_wsgi
Graham Dumpleton
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to mod_wsgi does not correctly remove the X-Client-IP header when processing requests from untrusted proxies. A remote attacker can pass a trusted proxy IP address via the X-Client-IP HTTP header and bypass implemented security restrictions.