statamic/cms is vulnerable to Access Control Bypass
53
Medium Risk
Statamic's ip_address content protection scheme matches its allow-list against the whole forwarded address chain from request()->ips() instead of the resolved client address. An unauthenticated visitor can place an allowed address anywhere in that chain through a crafted forwarding header, so protected content is served to a client whose real address was never on the list. Only sites that enable this non-default scheme behind configured trusted proxies are affected. The fix compares the allow-list against request()->ip(), so deployments behind a load balancer must list the balancer among their trusted proxies.
You are affected if you are using a version that falls within the vulnerable range and have the ip_address content protection scheme enabled with trusted proxies configured.
statamic/cms is vulnerable to Access Control Bypass in versions 6.6.0 - 6.32.0.
Upgrade the statamic/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.