CVE-2023-42282Server-Side Request Forgery in Node-ip

Severity
9.8CRITICALNVD
NVD8.1
EPSS
0.7%
top 27.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 8
Latest updateAug 13

Description

The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Patches

🔴Vulnerability Details

6
GHSA
ip SSRF improper categorization in isPublic2024-06-02
OSV
ip SSRF improper categorization in isPublic2024-06-02
OSV
CVE-2024-29415: The ip package through 22024-05-27
OSV
NPM IP package incorrectly identifies some private IP addresses as public2024-02-08
OSV
CVE-2023-42282: The ip package before 12024-02-08

📋Vendor Advisories

6
Red Hat
node-ip: Incomplete fix for CVE-2023-422822024-02-20
Ubuntu
NPM IP vulnerability2024-02-19
Microsoft
The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.2024-02-13
Red Hat
nodejs-ip: arbitrary code execution via the isPublic() function2024-02-08
Debian
CVE-2024-29415: node-ip - The ip package through 2.0.1 for Node.js might allow SSRF because some IP addres...2024

🕵️Threat Intelligence

1
Bleepingcomputer
Critical SAP flaw allows remote attackers to bypass authentication2024-08-13
CVE-2023-42282 — Server-Side Request Forgery in Node-ip | cvebase