VulnerabilityModified
CVE-2023-42282
The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.
CRITICAL 9.8EPSS 1.61%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.61%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.61% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- fedorindutny/ip
- Source
- cve@mitre.org
References
- https://cosmosofcyberspace.github.io/npm_ip_cve/npm_ip_cve.htmlExploit, Third Party Advisory
- https://github.com/indutny/node-ip/commit/6a3ada9b471b09d5f0f5be264911ab564bf67894Patch
- https://huntr.com/bounties/bfc3b23f-ddc0-4ee7-afab-223b07115ed3/Exploit, Technical Description
- https://security.netapp.com/advisory/ntap-20240315-0008/Third Party Advisory
- https://www.bleepingcomputer.com/news/security/dev-rejects-cve-severity-makes-his-github-repo-read-only/Press/Media Coverage
- https://cosmosofcyberspace.github.io/npm_ip_cve/npm_ip_cve.htmlExploit, Third Party Advisory
- https://github.com/indutny/node-ip/commit/6a3ada9b471b09d5f0f5be264911ab564bf67894Patch
- https://huntr.com/bounties/bfc3b23f-ddc0-4ee7-afab-223b07115ed3/Exploit, Technical Description
- https://security.netapp.com/advisory/ntap-20240315-0008/Third Party Advisory
- https://www.bleepingcomputer.com/news/security/dev-rejects-cve-severity-makes-his-github-repo-read-only/Press/Media Coverage
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.