ZeroHour

CVE-2023-42282

PoC ×2
CVSS 3.1
9.8 critical
EPSS
2%p75
Published
()
Modified
Description

The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

Vendors
fedorindutny
Products
ip
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.