Account Takeover - COCOAPODS

Vulnerability Details:

Broken email verification at "X-Forwarded-Host" header leads to Account takeover on cocoapods which is a dependency manager for Swift and Objective-C Cocoa projects.



PoC

















There was alot of huge companies affected from this critical vulnerability, after reported cocoapods team has fixed this vulnerability