CVE-2025-6504 Information
Jul 30, 2025
cve
Description
In HDP Server versions below 4.6.2.2978 on Linux unauthorized access could occur via IP spoofing using the X-Forwarded-For header.
Since XFF is a client-controlled header it could be spoofed allowing unauthorized access if the spoofed IP matched a whitelisted range.
This vulnerability could be exploited to bypass IP restrictions though valid user credentials would still be required for resource access.
Reference
Related CNNVD
CNNVD-202507-3607 (Published: 2025-07-29)
Share on: