Bypassing Server-Side Request Forgery filters by abusing a bug in Ruby’s native resolver
Summary This is a security advisory for a bug that I discovered in Resolv::getaddresses that enabled me to bypass multiple Server-Side Request Forgery filters. Applications…