The privateaddresscheck ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses
method, which is OS-dependent and should not be relied upon for security measures, such as when used to blacklist private network addresses to prevent server-side request forgery.
{ "nvd_published_at": null, "cwe_ids": [ "CWE-242" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:41:23Z" }