Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in a Node.js module used for identifying client IP addresses behind proxies could allow unauthenticated users to spoof their origin. This could undermine security controls like access restrictions and logging. The issue is a regression in how certain IP address ranges are trusted.
- Allows spoofing client IP addresses.
- Impacts IP-based access and rate limiting.
- Confirm if your applications use this module.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can reach this vulnerability by sending a specially crafted request to a web application that uses the affected Node.js module. The application must be configured with a specific type of incorrect trust subnet setting. By manipulating the `X-Forwarded-For` header, the attacker can trick the application into trusting their IP address, which can lead to various security bypasses.
- No authentication required.
- Malicious `X-Forwarded-For` header.
- Bypass IP-based security controls.
Live Threat
Current exploitation, exposure, and threat context
When the `proxy-addr` module is configured with a specific, improperly formatted IPv4-mapped IPv6 trust subnet, it can incorrectly trust all IPv4 addresses. This allows any unauthenticated client to forge the `X-Forwarded-For` header, potentially impacting IP-based access controls, rate limiting, geolocation, and audit logging mechanisms.
- Application access controls could be bypassed.
- Arbitrary client IPs may be trusted.
- Service integrity could be compromised.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Node.js `proxy-addr` module's vulnerability necessitates action from application owners and platform teams responsible for web services. The first practical step is to identify all instances of `proxy-addr` within your environment, determine their exposure to external network traffic, and confirm the business criticality of the services they support. Once ownership is established, a remediation plan can be developed based on the assessed risk.
- Application and platform teams own resolution.
- Verify external reachability and business impact.
- Plan upgrade or apply workarounds.