QID 375431
Date Published: 2021-04-06
QID 375431: Npm Package Netmask Octal Input Data Vulnerability
NPM is a package manager for the JavaScript programming language. It is the default package manager for the JavaScript runtime environment Node.js.
The Netmask class parses and understands IPv4 CIDR blocks so they can be explored and compared.
CVE-2021-29418: The netmask package before 2.0.1 for Node.js mishandles certain unexpected characters in an IP address string, such as an octal digit of 9
Affected versions:
Netmask Package before version to 2.0.1
QID Detection logic:(Authenticated)
It will execute command npm list | grep 'netmask' command to check the systeminformation version
Successful exploitation of this vulnerability could allows attackers to bypass access control that is based on IP addresses.
Solution
Customers are advised to update Netmask package 2.0.1 or later . Please refer the Vendor advisory link Netmask
Vendor References
- Netmask -
www.npmjs.com/package/netmask
CVEs related to QID 375431
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Netmask |
|