Impact
This vulnerability may allow attackers to spoof their IP address when your server is behind a reverse proxy.
Patches
Upgrade to v4.2.11 or later, and configure Config\App::$proxyIPs
.
Workarounds
Do not use $request->getIPAddress()
.
References
For more information
If you have any questions or comments about this advisory:
Impact
This vulnerability may allow attackers to spoof their IP address when your server is behind a reverse proxy.
Patches
Upgrade to v4.2.11 or later, and configure
Config\App::$proxyIPs
.Workarounds
Do not use
$request->getIPAddress()
.References
For more information
If you have any questions or comments about this advisory: