CVE-2020-13485: Critical severity verbb knock knock vulnerability
Published May 25, 2020
·Updated
The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.
Affected Software
2 affected componentsFixes available
verbb Knock Knock Craft Cms<1.2.8
composer/verbb/knock-knock<1.2.8
1.2.8
Event History
May 25, 2020
CVE Published
via MITRE·10:38 PM
Data Sourced
via MITRE·10:38 PM
Description
May 24, 2022
Advisory Published
via GitHub·05:18 PM
Frequently Asked Questions
1
What is the severity of CVE-2020-13485?
CVE-2020-13485 has a medium severity rating due to the potential for IP Whitelist bypass.
2
How do I fix CVE-2020-13485?
To fix CVE-2020-13485, update the Knock Knock plugin to version 1.2.8 or later.
3
What type of vulnerability is CVE-2020-13485?
CVE-2020-13485 is an IP Whitelist bypass vulnerability affecting the Knock Knock plugin for Craft CMS.
4
What software is affected by CVE-2020-13485?
CVE-2020-13485 affects the Knock Knock plugin for Craft CMS versions prior to 1.2.8.
5
Is there a public advisory for CVE-2020-13485?
Yes, there is a public advisory available for CVE-2020-13485 detailing the vulnerability and its impacts.