The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| cakephp/cakephp(Packagist) | 1.2.0 | 2.6.13 | N/A |
| cakephp/cakephp(Packagist) | 2.7.0-rc1 | 2.7.11 | N/A |
| cakephp/cakephp(Packagist) | 2.8.0-rc1 | 2.8.2 | N/A |
| cakephp/cakephp(Packagist) | 3.0.0-rc1 | 3.0.17 | N/A |
| cakephp/cakephp(Packagist) | 3.1.0-beta1 | 3.1.12 | N/A |
| cakephp/cakephp(Packagist) | 3.2.0-rc1 | 3.2.5 | N/A |
CVSS Metrics