Loading...
Loading...
lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to spoof the IP address and hide activities via a modified X-Forwarded-For header.
September 22, 2009
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2009-3287
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.