QID 995513

Date Published: 2023-10-05

QID 995513: Python (Pip) Security Update for pretix (GHSA-j9gq-w73w-9h6c)

An issue was discovered in pretix before 2023.7.1. Incorrect parsing of configuration files causes the application to trust unchecked X-Forwarded-For headers even though it has not been configured to do so. This can lead to IP address spoofing by users of the application.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-j9gq-w73w-9h6c for updates and patch information.
    Vendor References

    CVEs related to QID 995513

    Software Advisories
    Advisory ID Software Component Link
    GHSA-j9gq-w73w-9h6c pretix URL Logo github.com/advisories/GHSA-j9gq-w73w-9h6c