PT-2024-11204 · Unknown · Net::Ipaddress::Util

Published

2024-03-17

·

Updated

2024-03-18

·

CVE-2021-47156

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Net::IPAddress::Util versions prior to 5.000
Description The issue arises from the Net::IPAddress::Util module not properly handling extraneous zero characters in IP address strings. This can lead to attackers bypassing access control based on IP addresses in certain situations.
Recommendations For versions prior to 5.000, update to version 5.000 or later to resolve the issue. As a temporary workaround, consider validating IP addresses manually to ensure they do not contain extraneous zero characters, until the module is updated.

Fix

Weakness Enumeration

Related Identifiers

CVE-2021-47156

Affected Products

Net::Ipaddress::Util