CVE-2025-6504

In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header.  Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized access if the spoofed IP matched a whitelisted range. This vulnerability could be exploited to bypass IP restrictions, though valid user credentials would still be required for resource access.
Configurations

No configuration.

History

29 Jul 2025, 14:15

Type Values Removed Values Added
CWE CWE-345

29 Jul 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-29 13:15

Updated : 2025-07-29 14:15


NVD link : CVE-2025-6504

Mitre link : CVE-2025-6504

CVE.ORG link : CVE-2025-6504


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity