--- gem: private_address_check cve: 2017-0909 url: https://github.com/jtdowney/private_address_check/pull/3 title: private_address_check Ruby Gem Blacklist Bypass privilege escalation date: 2017-11-09 description: | The private_address_check ruby gem before 0.4.1 is vulnerable to a bypass due to an incomplete blacklist of common private/local network addresses used to prevent server-side request forgery. cvss_v2: 7.5 cvss_v3: 9.8 patched_versions: - ">= 0.4.1"