Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-47154

Опубликовано: 18 мар. 2024
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

A vulnerability was found in the Perl module Net::CIDR::Lite, where extraneous zero characters at the start of an IP address string are not adequately handled. This flaw may enable attackers to circumvent IP address-based access controls in certain scenarios.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9perl-Net-CIDR-LiteNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2270058Perl-Net-CIDR-Lite: improper handling of extraneous zero characters in an IP address string

EPSS

Процентиль: 9%
0.00035
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 1 года назад

The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 6.3
nvd
больше 1 года назад

The Net::CIDR::Lite module before 0.22 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

CVSS3: 6.3
debian
больше 1 года назад

The Net::CIDR::Lite module before 0.22 for Perl does not properly cons ...

suse-cvrf
около 1 года назад

Security update for perl-Net-CIDR-Lite

CVSS3: 6.3
redos
около 1 года назад

Уязвимость perl-Net-CIDR-Lite

EPSS

Процентиль: 9%
0.00035
Низкий

6.3 Medium

CVSS3