PT-2024-4391 · Unknown+4 · Net-Cidr-Lite+4

Published

2024-03-17

·

Updated

2025-05-28

·

CVE-2021-47154

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Net::CIDR::Lite versions prior to 0.22
Description The issue is related to the improper handling of extraneous zero characters at the beginning of an IP address string. This can allow attackers to bypass access control based on IP addresses in certain situations.
Recommendations For versions prior to 0.22, update to version 0.22 or later to resolve the issue. As a temporary workaround, consider validating IP address strings to remove any leading zero characters before processing them with the Net::CIDR::Lite module.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2024-04890
CVE-2021-47154
DLA-3770-1
OESA-2024-1303
OESA-2024-1304
OESA-2024-1305
OPENSUSE-SU-2024_1256-1
SUSE-SU-2024:1256-1
SUSE-SU-2024_1256-1
USN-6712-1

Affected Products

Linuxmint
Net-Cidr-Lite
Red Os
Suse
Ubuntu