CVE-2023-42282

CRITICAL9.8EPSS 0.67%

NPM IP package incorrectly identifies some private IP addresses as public

發布日:2024/2/8修改日:2026/4/28

描述

The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

參考連結(9)