← back
CVE-2015-3224

CVE-2015-3224

50Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 45%
from disclosure to weapon0 days
Published on NVDJul 26
1st PoCJun 16
metasploitJun 16
exploitation probability
45%top 1% of all CVEs
observed exploitation
nono source reports it
6 public exploit(s)
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.