
Cloud Vulnerability DB
A community-led vulnerabilities database
The Knock Knock plugin before version 1.2.8 for Craft CMS contained a security vulnerability identified as CVE-2020-13485. The vulnerability allowed attackers to bypass IP Whitelist restrictions via manipulation of the X-Forwarded-For HTTP header. This security issue was discovered and reported in May 2020 (Limpid Security).
The vulnerability existed due to improper implementation of the IP-Whitelist mechanism, which compared whitelisted IP addresses against the X-Forwarded-For header value without proper validation. This design flaw allowed attackers to bypass access restrictions by manipulating the X-Forwarded-For header in their HTTP requests. The vulnerability had a CVSS score of 6.4, indicating a medium severity level (CISA).
The vulnerability allowed unauthorized users to bypass IP-based access restrictions, potentially gaining access to protected resources and areas of the website that should have been restricted based on IP whitelist rules (Limpid Security).
The vulnerability was relatively simple to exploit, requiring only the ability to manipulate HTTP headers in requests. An attacker could bypass the IP whitelist protection by including a whitelisted IP address in the X-Forwarded-For header of their request, regardless of their actual IP address (Limpid Security).
The vulnerability was patched in version 1.2.8 of the Knock Knock plugin. The fix addressed the IP spoofing issue by implementing proper validation of user IP addresses and preventing bypass through header manipulation. Users were advised to update to version 1.2.8 or later to protect against this vulnerability (Knock Knock Changelog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."