CVE-2025-6504
29.07.2025, 13:15
In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header. Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized access if the spoofed IP matched a whitelisted range. This vulnerability could be exploited to bypass IP restrictions, though valid user credentials would still be required for resource access.Enginsight
| Vendor | Product | Version |
|---|---|---|
| progress | hybrid_data_pipeline | 𝑥 < 4.6.2.2978 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration