CVE-2018-3759 is a time-of-check time-of-use (TOCTOU) race condition affecting the private_address_check Ruby gem before version 0.5.0. This vulnerability allows an attacker to bypass address checks by manipulating DNS entries with a zero TTL, causing an initial public address resolution to become a private address upon subsequent resolution. With a CVSS score of 3.7 (LOW), it has a network attack vector and high attack complexity, potentially leading to low confidentiality impact. There is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.5.0CPE matchmatch criteria | cpe:2.3:a:private_address_check_project:private_address_check:*:*:*:*:*:ruby:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.