Vulnerability Details CVE-2020-28483
This affects all versions of package github.com/gin-gonic/gin. When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.8%
CVSS Severity
CVSS v3 Score 7.1
CVSS v2 Score 5.8
Products affected by CVE-2020-28483
-
cpe:2.3:a:gin-gonic:gin:-
-
cpe:2.3:a:gin-gonic:gin:0.1
-
cpe:2.3:a:gin-gonic:gin:0.2
-
cpe:2.3:a:gin-gonic:gin:0.3
-
cpe:2.3:a:gin-gonic:gin:0.4
-
cpe:2.3:a:gin-gonic:gin:0.5
-
cpe:2.3:a:gin-gonic:gin:0.6
-
cpe:2.3:a:gin-gonic:gin:0.7.4
-
cpe:2.3:a:gin-gonic:gin:1.0
-
cpe:2.3:a:gin-gonic:gin:1.1
-
cpe:2.3:a:gin-gonic:gin:1.1.1
-
cpe:2.3:a:gin-gonic:gin:1.1.2
-
cpe:2.3:a:gin-gonic:gin:1.1.3
-
cpe:2.3:a:gin-gonic:gin:1.1.4
-
cpe:2.3:a:gin-gonic:gin:1.2
-
cpe:2.3:a:gin-gonic:gin:1.3.0
-
Gin-Gonic
»
Gin
»
Version: 1.3.1-0.20190301021747-ccb9e902956d
cpe:2.3:a:gin-gonic:gin:1.3.1-0.20190301021747-ccb9e902956d
-
cpe:2.3:a:gin-gonic:gin:1.4.0
-
cpe:2.3:a:gin-gonic:gin:1.5.0
-
cpe:2.3:a:gin-gonic:gin:1.6.0
-
cpe:2.3:a:gin-gonic:gin:1.6.1
-
cpe:2.3:a:gin-gonic:gin:1.6.2
-
cpe:2.3:a:gin-gonic:gin:1.6.3