Back to search
CVE-2018-3759
Published: Jun 13, 2018
Modified: Sep 16, 2024
PUBLISHED
Description
private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to the address the socket uses not being checked. DNS entries with a TTL of 0 can trigger this case where the initial resolution is a public address but the subsequent resolution is a private address.
| Vendor | Product | Versions |
|---|---|---|
HackerOne | private_address_check ruby gem | affected 0.5.0 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now