When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7.
{
"cwe_ids": [
"CWE-113",
"CWE-444"
],
"github_reviewed": true,
"github_reviewed_at": "2021-05-12T21:46:50Z",
"severity": "HIGH",
"nvd_published_at": "2021-01-20T18:15:00Z"
}