CVE-2021-4226: RSFirewall < 1.1.25 - IP Block Bypass
Published Dec 15, 2022
·Updated
RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented.
Affected Software
1 affected component
rsjoomla Rsfirewall\! Wordpress<1.1.25
Event History
Dec 15, 2022
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-4226?
CVE-2021-4226 is considered a medium severity vulnerability.
2
How do I fix CVE-2021-4226?
To fix CVE-2021-4226, update RSFirewall! to version 1.1.25 or later.
3
What type of vulnerability is CVE-2021-4226?
CVE-2021-4226 is a bypass vulnerability related to IP address identification in HTTP headers.
4
Which software is affected by CVE-2021-4226?
CVE-2021-4226 affects RSFirewall! versions prior to 1.1.25.
5
Can CVE-2021-4226 lead to security risks?
Yes, CVE-2021-4226 can lead to spoofing of IP addresses, compromising security.