Description


The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

Related CPE's



Weaknesses



CWE-704

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7.5 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-03-31T16:15:16.037Z

4 years ago

Last modified

2024-11-21T05:01:36.290Z

1 year ago