ip SSRF improper categorization in isPublic
High severity
GitHub Reviewed
Published
Jun 2, 2024
to the GitHub Advisory Database
•
Updated Sep 3, 2024
Description
Published by the National Vulnerability Database
May 27, 2024
Published to the GitHub Advisory Database
Jun 2, 2024
Reviewed
Jun 2, 2024
Last updated
Sep 3, 2024
The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.
References