CVE-2020-37056 | Crystal Shard http-protection up to 0.2.0 Header X-Forwarded-For/X-Client-IP/X-Real-IP authentication spoofing (Exploit 48533 / EUVD-2020-30926)
A vulnerability categorized as critical has been discovered in Crystal Shard http-protection up to 0.2.0. Impacted is an unknown function of the component Header Handler. Such manipulation of the argument X-Forwarded-For/X-Client-IP/X-Real-IP leads to authentication bypass by spoofing.
This vulnerability is listed as CVE-2020-37056. The attack may be performed from remote. In addition, an exploit is available.