HIGH8.1
GHSA-2p57-rm9w-gvfp
ip SSRF improper categorization in isPublic
Details
The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/ip
Introduced in:
0No fixed version published yet for ip (npm). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-29415[ADVISORY]
- https://github.com/indutny/node-ip/issues/150[WEB]
- https://github.com/indutny/node-ip/pull/143[WEB]
- https://github.com/indutny/node-ip/pull/144[WEB]
- https://github.com/indutny/node-ip[PACKAGE]
- https://security.netapp.com/advisory/ntap-20250117-0010[WEB]