Vulnerability record · CVE-2015-3224 · published 26 July 2015
CVE-2015-3224: Web Console IP whitelist bypass via X-Forwarded-For header
Rubyonrails · Web Console
Web Console before 2.1.3, used with Ruby on Rails 3.x and 4.x, trusts the X-Forwarded-For header when determining a client's IP address. This lets a remote attacker spoof that header and bypass the whitelisted_ips access control that is meant to keep the console reachable only from trusted addresses.
Description
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.
AV:N/AC:M/Au:N/C:N/I:P/A:N
Automated analysis
high priorityThe flaw allows bypass of an access control protecting an interactive Rails console, and EPSS is high at the 98.7th percentile despite the medium CVSS 2.0 score.
What it is
Web Console before 2.1.3, used with Ruby on Rails 3.x and 4.x, trusts the X-Forwarded-For header when determining a client's IP address. This lets a remote attacker spoof that header and bypass the whitelisted_ips access control that is meant to keep the console reachable only from trusted addresses.
Impact
An attacker who can reach the console endpoint gains access to the Web Console despite the IP whitelist, exposing an interactive Rails execution environment. The CVSS 2.0 vector shows partial integrity impact only, with no confidentiality or availability impact recorded.
Attack surface
Reached over the network against the Web Console endpoint; the CVSS vector AV:N/AC:M/Au:N indicates no authentication is required, though the crafted request must satisfy the medium complexity condition. No user interaction is indicated.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is 0.44708 (98.7th percentile), indicating a high modeled likelihood of exploitation activity.
What to do
- Upgrade Web Console to 2.1.3 or later, which is the fixed release named in the advisory.
- If upgrade is not immediately possible, restrict network access to the console endpoint at the proxy or firewall layer rather than relying on whitelisted_ips.
- Strip or normalize client-supplied X-Forwarded-For headers at the reverse proxy so the application cannot be tricked by spoofed values.
- Disable Web Console in production environments where it is not required.
Detection
- Review Web Console access logs for requests whose X-Forwarded-For value does not match the actual source address.
- Alert on console requests originating from addresses outside the intended whitelist.
- Monitor for anomalous or unexpected console sessions, especially from external or untrusted networks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-3224 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-3224), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.