Уязвимость некорректной работы методов Is*() для IPv4-маппированных IPv6-адресов
Описание
Различные методы Is*
(IsPrivate
, IsLoopback
и т.д.) работали некорректно для IPv4-маппированных IPv6-адресов, возвращая false
для адресов, которые в традиционной IPv4-форме вернули бы true
.
Тип уязвимости
Некорректная обработка данных
Ссылки
- Mailing ListThird Party Advisory
- Patch
- Issue Tracking
- Release Notes
- Third Party Advisory
- Mailing ListThird Party Advisory
- Patch
- Issue Tracking
- Release Notes
- Third Party Advisory
Уязвимые конфигурации
Одно из
EPSS
9.8 Critical
CVSS3
Дефекты
Связанные уязвимости
The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
The various Is methods (IsPrivate, IsLoopback, etc) did not work as expected for IPv4-mapped IPv6 addresses, returning false for addresses which would return true in their traditional IPv4 forms.
Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip
The various Is methods (IsPrivate, IsLoopback, etc) did not work as ex ...
EPSS
9.8 Critical
CVSS3