{"api_version":"1","generated_at":"2026-07-23T14:16:06+00:00","cve":"CVE-2021-29662","urls":{"html":"https://cve.report/CVE-2021-29662","api":"https://cve.report/api/cve/CVE-2021-29662.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-29662","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-29662"},"summary":{"title":"CVE-2021-29662","description":"The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2021-03-31 18:15:00","updated_at":"2023-08-08 14:21:00"},"problem_types":["CWE-704"],"metrics":[],"references":[{"url":"https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/","name":"https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/","refsource":"MISC","tags":[],"title":"Security Issues in Perl IP Address distros - House Absolute(ly) Pointless","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-018.md","name":"https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-018.md","refsource":"MISC","tags":[],"title":"security/SICK-2021-018.md at master · sickcodes/security · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://security.netapp.com/advisory/ntap-20210604-0002/","name":"https://security.netapp.com/advisory/ntap-20210604-0002/","refsource":"CONFIRM","tags":[],"title":"CVE-2021-29662 Perl Vulnerability in NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/houseabsolute/Data-Validate-IP","name":"https://github.com/houseabsolute/Data-Validate-IP","refsource":"MISC","tags":[],"title":"GitHub - houseabsolute/Data-Validate-IP: IPv4 and IPv6 validation methods","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://sick.codes/sick-2021-018/","name":"https://sick.codes/sick-2021-018/","refsource":"MISC","tags":[],"title":"CVE-2021-29662 - Perl module Data::Validate::IP - Improper Input Validation of octal literals in Perl Data::Validate::IP v0.29 and below results in indeterminate SSRF & RFI vulnerabilities. - Sick Codes - Security Research, Hardware & Software Hacking, Consulting, Linux, IoT, Cloud, Embedded, Arch, Tweaks & Tips!","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/houseabsolute/Data-Validate-IP/commit/3bba13c819d616514a75e089badd75002fd4f14e","name":"https://github.com/houseabsolute/Data-Validate-IP/commit/3bba13c819d616514a75e089badd75002fd4f14e","refsource":"MISC","tags":[],"title":"Update security note in docs to include mention of is_ip() and friends · houseabsolute/Data-Validate-IP@3bba13c · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-29662","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-29662","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"29662","vulnerable":"1","versionEndIncluding":"0.29","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"data\\","cpe5":"\\","cpe6":"validate\\","cpe7":"\\","cpe8":"ip_project","cpe9":"data\\","cpe10":"\\","cpe11":"validate\\","cpe12":"\\","cpe13":"ip"},{"cve_year":"2021","cve_id":"29662","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"netapp","cpe5":"snapcenter","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-29662","qid":"179403","title":"Debian Security Update for libdata-validate-ip-perl (CVE-2021-29662)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2021-29662","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/","url":"https://blog.urth.org/2021/03/29/security-issues-in-perl-ip-address-distros/"},{"url":"https://github.com/houseabsolute/Data-Validate-IP/commit/3bba13c819d616514a75e089badd75002fd4f14e","refsource":"MISC","name":"https://github.com/houseabsolute/Data-Validate-IP/commit/3bba13c819d616514a75e089badd75002fd4f14e"},{"refsource":"MISC","name":"https://sick.codes/sick-2021-018/","url":"https://sick.codes/sick-2021-018/"},{"refsource":"MISC","name":"https://github.com/houseabsolute/Data-Validate-IP","url":"https://github.com/houseabsolute/Data-Validate-IP"},{"refsource":"MISC","name":"https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-018.md","url":"https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-018.md"},{"refsource":"CONFIRM","name":"https://security.netapp.com/advisory/ntap-20210604-0002/","url":"https://security.netapp.com/advisory/ntap-20210604-0002/"}]}},"nvd":{"publishedDate":"2021-03-31 18:15:00","lastModifiedDate":"2023-08-08 14:21:00","problem_types":["CWE-704"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:data\\:\\:validate\\:\\:ip_project:data\\:\\:validate\\:\\:ip:*:*:*:*:*:perl:*:*","versionEndIncluding":"0.29","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"29662","Ordinal":"204872","Title":"CVE-2021-29662","CVE":"CVE-2021-29662","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"29662","Ordinal":"1","NoteData":"The Data::Validate::IP module through 0.29 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"29662","Ordinal":"2","NoteData":"2021-03-31","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"29662","Ordinal":"3","NoteData":"2021-06-04","Type":"Other","Title":"Modified"}]}}}