A critical vulnerability was discovered in React Server Components (Next.js). Our systems remain protected but we advise to update packages to newest version. Learn More

CloudPlatform should by default allow multiple X-Forwarded-For headers

Found in

EPiServer.CloudPlatform.Cms 1.0.2

Fixed in

EPiServer.CloudPlatform.Cms 1.0.3

(Or a related package)

Created

Nov 22, 2021

Updated

Nov 30, 2021

Area

CMS Core

State

Closed, Fixed and tested


Description

When you requested an IP endpoint (such as https://<sitedomain>/ip), the CloudPlatform IP address was shown instead of your own IP address. CloudPlatform should by default allow multiple X-Forwarded-For headers.