← Vulnerability feed

Vulnerability record · CVE-2015-3224 · published 26 July 2015

CVE-2015-3224: Web Console IP whitelist bypass via X-Forwarded-For header

Rubyonrails · Web Console

Web Console before 2.1.3, used with Ruby on Rails 3.x and 4.x, trusts the X-Forwarded-For header when determining a client's IP address. This lets a remote attacker spoof that header and bypass the whitelisted_ips access control that is meant to keep the console reachable only from trusted addresses.

4.3 CVSS 2.0 Medium EPSS 45% · top 1.3% CWE-284 · Improper access control
4.3CVSS 2.0 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote attackers to bypass the whitelisted_ips protection mechanism via a crafted request.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw allows bypass of an access control protecting an interactive Rails console, and EPSS is high at the 98.7th percentile despite the medium CVSS 2.0 score.

What it is

Web Console before 2.1.3, used with Ruby on Rails 3.x and 4.x, trusts the X-Forwarded-For header when determining a client's IP address. This lets a remote attacker spoof that header and bypass the whitelisted_ips access control that is meant to keep the console reachable only from trusted addresses.

Impact

An attacker who can reach the console endpoint gains access to the Web Console despite the IP whitelist, exposing an interactive Rails execution environment. The CVSS 2.0 vector shows partial integrity impact only, with no confidentiality or availability impact recorded.

Attack surface

Reached over the network against the Web Console endpoint; the CVSS vector AV:N/AC:M/Au:N indicates no authentication is required, though the crafted request must satisfy the medium complexity condition. No user interaction is indicated.

Exploitation

Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is 0.44708 (98.7th percentile), indicating a high modeled likelihood of exploitation activity.

What to do

  • Upgrade Web Console to 2.1.3 or later, which is the fixed release named in the advisory.
  • If upgrade is not immediately possible, restrict network access to the console endpoint at the proxy or firewall layer rather than relying on whitelisted_ips.
  • Strip or normalize client-supplied X-Forwarded-For headers at the reverse proxy so the application cannot be tricked by spoofed values.
  • Disable Web Console in production environments where it is not required.

Detection

  • Review Web Console access logs for requests whose X-Forwarded-For value does not match the actual source address.
  • Alert on console requests originating from addresses outside the intended whitelist.
  • Monitor for anomalous or unexpected console sessions, especially from external or untrusted networks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-3224 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed10.0CVE-2026-21962Oracle HTTP Server and WebLogic Proxy Plug-in improper access controlOracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in suppor…KEVEPSS 71%analysed10.0CVE-2026-34908Ubiquiti UniFi OS improper access control allows unauthorized system changesUniFi OS devices contain an improper access control flaw (CWE-284) that lets a network-reachable actor make unauthorized changes to the system. The C…KEVEPSS 15%analysed10.0CVE-2026-48907JCE editor for Joomla allows unauthenticated profile creation and PHP uploadThe JCE editor extension for Joomla permits unauthenticated users to create new editor profiles, which leads to upload and execution of PHP code. Thi…KEVEPSS 16%analysed9.8CVE-2026-35616FortiClientEMS improper access control allows unauthenticated code executionFortinet FortiClientEMS 7.4.5 through 7.4.6 contains an improper access control flaw (CWE-284) that lets an unauthenticated attacker send crafted req…KEVEPSS 9.1%analysed7.5CVE-2025-31125Vite dev server improper access control exposes arbitrary filesVite's dev server fails to restrict file access when a request uses the ?inline&import or ?raw?import query patterns, allowing content of files that …KEVEPSS 65%analysed9.1CVE-2025-12480Gladinet Triofox improper access control exposes setup pagesTriofox versions before 16.7.10368.56560 leave initial setup pages reachable after setup is complete due to improper access control (CWE-284). Becaus…KEVEPSS 95%analysed8.8CVE-2025-33073Windows SMB improper access control allows privilege elevationWindows SMB contains an improper access control flaw (CWE-284) that lets an authorized attacker elevate privileges over the network. Microsoft rates …KEVEPSS 83%analysed

Source: NIST National Vulnerability Database (record CVE-2015-3224), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.