PT-2024-11204 · Unknown · Net::Ipaddress::Util
Published
2024-03-17
·
Updated
2024-03-18
·
CVE-2021-47156
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Net::IPAddress::Util versions prior to 5.000
Description
The issue arises from the Net::IPAddress::Util module not properly handling extraneous zero characters in IP address strings. This can lead to attackers bypassing access control based on IP addresses in certain situations.
Recommendations
For versions prior to 5.000, update to version 5.000 or later to resolve the issue. As a temporary workaround, consider validating IP addresses manually to ensure they do not contain extraneous zero characters, until the module is updated.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Net::Ipaddress::Util