private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check...
Vulnerability Description
private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to the address the socket uses not being checked. DNS entries with a TTL of 0 can trigger this case where the initial resolution is a public address but the subsequent resolution is a private address.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-3759
Credits & Attribution
No credits recorded in the NVD database.
References
More from HackerOne
View All →Affected Vendor
HackerOne
View all reports →