Description
The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-78xj-cgh5-2h22 | NPM IP package incorrectly identifies some private IP addresses as public |
Ubuntu USN |
USN-6643-1 | NPM IP vulnerability |
References
History
Thu, 15 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 Nov 2024 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat openshift Devspaces
|
|
| CPEs | cpe:/a:redhat:openshift_devspaces:3::el8 | |
| Vendors & Products |
Redhat openshift Devspaces
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-15T19:42:13.205Z
Reserved: 2023-09-08T00:00:00.000Z
Link: CVE-2023-42282
Updated: 2024-08-02T19:16:51.020Z
Status : Modified
Published: 2024-02-08T17:15:10.840
Modified: 2025-05-15T20:15:26.367
Link: CVE-2023-42282
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA
Ubuntu USN