Количество 2
Количество 2
CVE-2017-0904
The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-dependent and should not be relied upon for security measures, such as when used to blacklist private network addresses to prevent server-side request forgery.
GHSA-hxhj-hp9m-qwc4
private_address_check vulnerable to bypass of Resolv.getaddresses method
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2017-0904 The private_address_check ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-dependent and should not be relied upon for security measures, such as when used to blacklist private network addresses to prevent server-side request forgery. | CVSS3: 8.1 | 1% Низкий | около 8 лет назад | |
GHSA-hxhj-hp9m-qwc4 private_address_check vulnerable to bypass of Resolv.getaddresses method | 1% Низкий | около 8 лет назад |
Уязвимостей на страницу