LOW
GHSA-78xj-cgh5-2h22
NPM IP package incorrectly identifies some private IP addresses as public
Quick fix
GHSA-78xj-cgh5-2h22 — ip: upgrade to the fixed version with the command below.
npm install ip@2.0.1Details
The `isPublic()` function in the NPM package `ip` doesn't correctly identify certain private IP addresses in uncommon formats such as `0x7F.1` as private. Instead, it reports them as public by returning `true`. This can lead to security issues such as Server-Side Request Forgery (SSRF) if `isPublic()` is used to protect sensitive code paths when passed user input. Versions 1.1.9 and 2.0.1 fix the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-42282[ADVISORY]
- https://github.com/JoshGlazebrook/socks/issues/93#issue-2128357447[WEB]
- https://github.com/github/advisory-database/pull/3504#issuecomment-1937179999[WEB]
- https://github.com/indutny/node-ip/pull/138[WEB]
- https://github.com/indutny/node-ip/commit/32f468f1245574785ec080705737a579be1223aa[WEB]
- https://github.com/indutny/node-ip/commit/6a3ada9b471b09d5f0f5be264911ab564bf67894[WEB]
- https://cosmosofcyberspace.github.io/npm_ip_cve/npm_ip_cve.html[WEB]
- https://github.com/indutny/node-ip[PACKAGE]