CVE-2020-13485: Incorrect Comparison
(updated )
The knock-knock plugin for Craft CMS may allow a user who injects a specially crafted X-Forwarded-For
HTTP header to bypass IP restrictions.
References
Detect and mitigate CVE-2020-13485 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →