{"id":"GHSA-3v3c-r5v2-68ph","summary":"private_address_check contains Incomplete List of Disallowed Inputs","details":"The private_address_check ruby gem before 0.4.1 is vulnerable to a bypass due to an incomplete blacklist of common private/local network addresses used to prevent server-side request forgery.","aliases":["CVE-2017-0909"],"modified":"2024-12-06T05:34:39.948583Z","published":"2017-11-30T23:14:55Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T20:56:20Z","nvd_published_at":null,"cwe_ids":["CWE-184"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-0909"},{"type":"WEB","url":"https://github.com/jtdowney/private_address_check/pull/3"},{"type":"WEB","url":"https://hackerone.com/reports/288950"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-3v3c-r5v2-68ph"},{"type":"PACKAGE","url":"https://github.com/jtdowney/private_address_check"}],"affected":[{"package":{"name":"private_address_check","ecosystem":"RubyGems","purl":"pkg:gem/private_address_check"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.1"}]}],"versions":["0.1.0","0.2.0","0.3.0","0.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2017/11/GHSA-3v3c-r5v2-68ph/GHSA-3v3c-r5v2-68ph.json"}}],"schema_version":"1.9.0"}