CVE-2025-6504
Severity CVSS v4.0:
Pending analysis
Type:
CWE-345
Insufficient Verification of Data Authenticity
Publication date:
29/07/2025
Last modified:
02/10/2025
Description
In HDP Server versions below 4.6.2.2978 on Linux, unauthorized access could occur via IP spoofing using the X-Forwarded-For header. <br />
<br />
Since XFF is a client-controlled header, it could be spoofed, allowing unauthorized access if the spoofed IP matched a whitelisted range.<br />
<br />
<br />
This vulnerability could be exploited to bypass IP restrictions, though valid user credentials would still be required for resource access.
Impact
Base Score 3.x
8.40
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:progress:hybrid_data_pipeline:*:*:*:*:*:*:*:* | 4.6.2.2978 (excluding) | |
| cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



