hickory-proto is vulnerable to Improper Access Control
55
Medium Risk
Access-control checks compare client and server IP addresses without canonicalizing IPv4-mapped IPv6 addresses first. The same underlying IPv4 address expressed as an IPv4-mapped IPv6 address is treated as a distinct address, so allow lists, deny lists, and do-not-query filters can be bypassed. The fix canonicalizes addresses before matching.
You are affected if you are using a version that falls within the vulnerable range and you rely on IP allow/deny lists, do-not-query filters, or client access control
hickory-proto is vulnerable to Improper Access Control in versions 0.26.0 - 0.26.1.
Upgrade the hickory-proto library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.