CVE-2023-42282
08.02.2024, 17:15
The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.
| Vendor | Product | Version |
|---|---|---|
| fedorindutny | ip | 𝑥 < 1.1.9 |
| fedorindutny | ip | 2.0.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| node-ip |
|
References