Horizon Alert
Summary of the vulnerability and why it matters
This advisory addresses a vulnerability in Zoraxy software that could allow attackers to spoof their origin by manipulating forwarded headers over IPv6. This could potentially bypass access controls based on IP addresses. The main concern is confirming if this technology is in use and exposed to potential threats.
- Attackers can impersonate user IPs.
- Critical for any systems using this software.
- Verify software usage and exposure.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can exploit this by connecting to the Zoraxy service over IPv6. By sending specially crafted requests with forged `X-Forwarded-For` headers, the attacker can trick Zoraxy into believing the request originates from an IP address that is authorized. This allows the attacker to bypass IP-based access controls and potentially reach other sensitive functionalities or data within the application.
- Entry condition: Network access over IPv6.
- Trigger point: Sending custom IPv6 `X-Forwarded-For` headers.
- Resulting risk: Bypass IP access controls.
Live Threat
Current exploitation, exposure, and threat context
When Zoraxy improperly parses IPv6 addresses in the RemoteAddr field of forwarded headers, unauthenticated attackers can spoof their source IP address. This occurs when the software is configured to use IPv6 and attackers can send specially crafted requests to bypass IP-based access controls that rely on the accuracy of the forwarded client IP.
- Network access controls could be bypassed.
- Attackers spoof IP addresses via forwarded headers.
- Unauthorized access to services may occur.
Operational Fix
Recommended remediation, mitigation, and detection steps
Real-world mitigation likely involves infrastructure or platform teams responsible for the Zoraxy proxy deployment. The initial step is to identify all instances of Zoraxy, confirm their exposure to IPv6 networks and any business-critical functions they support, and then assign an owner for remediation planning.
- Identify affected Zoraxy instances.
- Verify IPv6 reachability and business impact.
- Plan and coordinate remediation efforts.