When gin is exposed directly to the internet, a client's IP can be spoofed by setting the X-Forwarded-For header. This affects all versions of package github.com/gin-gonic/gin under 1.7.7.
{ "cwe_ids": [ "CWE-113", "CWE-444" ], "github_reviewed": true, "github_reviewed_at": "2021-05-12T21:46:50Z", "severity": "HIGH", "nvd_published_at": "2021-01-20T18:15:00Z" }