CVE-2024-44930: Serilog-Contrib Serilog-Enrichers-Clientinfo
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Serilog before v2.1.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as a value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.
Affected products
- Serilog-Contrib Serilog-Enrichers-Clientinfo: before 2.1.0 (fixed in 2.1.0)
Published 2024-08-29. Last modified 2026-06-17.