The privateaddresscheck ruby gem before 0.4.0 is vulnerable to a bypass due to use of Ruby's Resolv.getaddresses method, which is OS-dependent and should not be relied upon for security measures, such as when used to blacklist private network addresses to prevent server-side request forgery.
{
"severity": "MODERATE",
"nvd_published_at": null,
"github_reviewed": true,
"cwe_ids": [
"CWE-242"
],
"github_reviewed_at": "2020-06-16T21:41:23Z"
}