CVE-2019-17240: Critical severity bludit vulnerability
Published Oct 6, 2019
·Updated
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many different forged X-Forwarded-For or Client-IP HTTP headers.
Affected Software
1 affected component
Bludit bludit=3.9.2
Event History
Oct 6, 2019
CVE Published
via MITRE·06:32 PM
Data Sourced
via MITRE·06:32 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this Bludit vulnerability?
The vulnerability ID for this Bludit vulnerability is CVE-2019-17240.
2
What is the title of this Bludit vulnerability?
The title of this Bludit vulnerability is 'bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism'.
3
What is the severity level of CVE-2019-17240?
CVE-2019-17240 has a severity level of critical.
4
What software version is affected by CVE-2019-17240?
Bludit version 3.9.2 is affected by CVE-2019-17240.
5
How can attackers exploit CVE-2019-17240?
Attackers can exploit CVE-2019-17240 by using many different forged X-Forwarded-For or Client-IP HTTP headers to bypass the brute-force protection mechanism.