CVE Vulnerabilities

CVE-2020-8984

Origin Validation Error

Published: Mar 24, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

lib/NSSDropbox.php in ZendTo prior to 5.22-2 Beta allowed IP address spoofing via the X-Forwarded-For header.

Weakness

The product does not properly verify that the source of data or communication is valid.

Affected Software

NameVendorStart VersionEnd Version
ZendtoZend3.10 (including)3.10 (including)
ZendtoZend3.11 (including)3.11 (including)
ZendtoZend3.12 (including)3.12 (including)
ZendtoZend3.13 (including)3.13 (including)
ZendtoZend3.20 (including)3.20 (including)
ZendtoZend3.51 (including)3.51 (including)
ZendtoZend3.52 (including)3.52 (including)
ZendtoZend3.53 (including)3.53 (including)
ZendtoZend3.54 (including)3.54 (including)
ZendtoZend3.55 (including)3.55 (including)
ZendtoZend3.56-2 (including)3.56-2 (including)
ZendtoZend3.57 (including)3.57 (including)
ZendtoZend3.58 (including)3.58 (including)
ZendtoZend3.59 (including)3.59 (including)
ZendtoZend3.60 (including)3.60 (including)
ZendtoZend3.61 (including)3.61 (including)
ZendtoZend3.62 (including)3.62 (including)
ZendtoZend3.63 (including)3.63 (including)
ZendtoZend3.64 (including)3.64 (including)
ZendtoZend3.65 (including)3.65 (including)
ZendtoZend3.70-2 (including)3.70-2 (including)
ZendtoZend3.71 (including)3.71 (including)
ZendtoZend3.72 (including)3.72 (including)
ZendtoZend3.73 (including)3.73 (including)
ZendtoZend3.74 (including)3.74 (including)
ZendtoZend3.75 (including)3.75 (including)
ZendtoZend3.90 (including)3.90 (including)
ZendtoZend3.91 (including)3.91 (including)
ZendtoZend3.92 (including)3.92 (including)
ZendtoZend3.93 (including)3.93 (including)
ZendtoZend3.94 (including)3.94 (including)
ZendtoZend4.00 (including)4.00 (including)
ZendtoZend4.01 (including)4.01 (including)
ZendtoZend4.02 (including)4.02 (including)
ZendtoZend4.03-3 (including)4.03-3 (including)
ZendtoZend4.05-2 (including)4.05-2 (including)
ZendtoZend4.06-2 (including)4.06-2 (including)
ZendtoZend4.07-1 (including)4.07-1 (including)
ZendtoZend4.08-4 (including)4.08-4 (including)
ZendtoZend4.09-1 (including)4.09-1 (including)
ZendtoZend4.10-4 (including)4.10-4 (including)
ZendtoZend4.10-5 (including)4.10-5 (including)
ZendtoZend4.11-1 (including)4.11-1 (including)
ZendtoZend4.11-2 (including)4.11-2 (including)
ZendtoZend4.11-3 (including)4.11-3 (including)
ZendtoZend4.11-4 (including)4.11-4 (including)
ZendtoZend4.11-5 (including)4.11-5 (including)
ZendtoZend4.11-7 (including)4.11-7 (including)
ZendtoZend4.11-8 (including)4.11-8 (including)
ZendtoZend4.11-9 (including)4.11-9 (including)
ZendtoZend4.11-10 (including)4.11-10 (including)
ZendtoZend4.11-11 (including)4.11-11 (including)
ZendtoZend4.11-12 (including)4.11-12 (including)
ZendtoZend4.11-13 (including)4.11-13 (including)
ZendtoZend4.11-14 (including)4.11-14 (including)
ZendtoZend4.12-5 (including)4.12-5 (including)
ZendtoZend4.12-6 (including)4.12-6 (including)
ZendtoZend4.13-1 (including)4.13-1 (including)
ZendtoZend4.20-2 (including)4.20-2 (including)
ZendtoZend4.20-3 (including)4.20-3 (including)
ZendtoZend4.20-5 (including)4.20-5 (including)
ZendtoZend4.20-6 (including)4.20-6 (including)
ZendtoZend4.20-7 (including)4.20-7 (including)
ZendtoZend4.25-3 (including)4.25-3 (including)
ZendtoZend4.27-1 (including)4.27-1 (including)
ZendtoZend4.27-2 (including)4.27-2 (including)
ZendtoZend4.27-4 (including)4.27-4 (including)
ZendtoZend4.27-5 (including)4.27-5 (including)
ZendtoZend4.27-6 (including)4.27-6 (including)
ZendtoZend4.27-7 (including)4.27-7 (including)
ZendtoZend4.28-1 (including)4.28-1 (including)
ZendtoZend4.28-2 (including)4.28-2 (including)
ZendtoZend5.00-1 (including)5.00-1 (including)
ZendtoZend5.00-2 (including)5.00-2 (including)
ZendtoZend5.01-5 (including)5.01-5 (including)
ZendtoZend5.02-5 (including)5.02-5 (including)
ZendtoZend5.03-1 (including)5.03-1 (including)
ZendtoZend5.04-7 (including)5.04-7 (including)
ZendtoZend5.09-13 (including)5.09-13 (including)
ZendtoZend5.10-1 (including)5.10-1 (including)
ZendtoZend5.10-2 (including)5.10-2 (including)
ZendtoZend5.11-1 (including)5.11-1 (including)
ZendtoZend5.11-2 (including)5.11-2 (including)
ZendtoZend5.11-3 (including)5.11-3 (including)
ZendtoZend5.11-4 (including)5.11-4 (including)
ZendtoZend5.11-5 (including)5.11-5 (including)
ZendtoZend5.11-6 (including)5.11-6 (including)
ZendtoZend5.12-3-beta (including)5.12-3-beta (including)
ZendtoZend5.12-4-beta (including)5.12-4-beta (including)
ZendtoZend5.12-6-beta (including)5.12-6-beta (including)
ZendtoZend5.12-7-beta (including)5.12-7-beta (including)
ZendtoZend5.12-8-beta (including)5.12-8-beta (including)
ZendtoZend5.13-1 (including)5.13-1 (including)
ZendtoZend5.13-2 (including)5.13-2 (including)
ZendtoZend5.14-2-beta (including)5.14-2-beta (including)
ZendtoZend5.14-5-beta (including)5.14-5-beta (including)
ZendtoZend5.15-1 (including)5.15-1 (including)
ZendtoZend5.16-1-beta (including)5.16-1-beta (including)
ZendtoZend5.16-4-beta (including)5.16-4-beta (including)
ZendtoZend5.16-5-beta (including)5.16-5-beta (including)
ZendtoZend5.16-7-beta (including)5.16-7-beta (including)
ZendtoZend5.16-8-beta (including)5.16-8-beta (including)
ZendtoZend5.16.6-beta (including)5.16.6-beta (including)
ZendtoZend5.17-1 (including)5.17-1 (including)
ZendtoZend5.17-2 (including)5.17-2 (including)
ZendtoZend5.17-3 (including)5.17-3 (including)
ZendtoZend5.17-4 (including)5.17-4 (including)
ZendtoZend5.17-5-beta (including)5.17-5-beta (including)
ZendtoZend5.17-6 (including)5.17-6 (including)
ZendtoZend5.18-1-beta (including)5.18-1-beta (including)
ZendtoZend5.18-2-beta (including)5.18-2-beta (including)
ZendtoZend5.19-1-production (including)5.19-1-production (including)
ZendtoZend5.20-1-beta (including)5.20-1-beta (including)
ZendtoZend5.20-2-beta (including)5.20-2-beta (including)
ZendtoZend5.20-3-beta (including)5.20-3-beta (including)
ZendtoZend5.20-5-beta (including)5.20-5-beta (including)
ZendtoZend5.20-6-beta (including)5.20-6-beta (including)
ZendtoZend5.20-7-beta (including)5.20-7-beta (including)
ZendtoZend5.20-8-beta (including)5.20-8-beta (including)
ZendtoZend5.20-9-beta (including)5.20-9-beta (including)
ZendtoZend5.21-1-production (including)5.21-1-production (including)
ZendtoZend5.21-2-production (including)5.21-2-production (including)
ZendtoZend5.22-1-beta (including)5.22-1-beta (including)

References