Описание
The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-29662
- https://github.com/houseabsolute/Data-Validate-IP/commit/3bba13c819d616514a75e089badd75002fd4f14e
- https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros
- https://github.com/houseabsolute/Data-Validate-IP
- https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-018.md
- https://security.netapp.com/advisory/ntap-20210604-0002
- https://sick.codes/sick-2021-018
Связанные уязвимости
The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.
The Data::Validate::IP module through 0.29 for Perl does not properly ...
Уязвимость модуля проверки IP Data::Validate::IP, связанная с неправильной авторизацией, позволяющая нарушителю оказать воздействие на целостность данных