QID 982003
QID 982003: Nodejs (npm) Security Update for private-ip (GHSA-43ch-2h55-2vj7)
Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker can perform a large range of requests to ARIN reserved IP ranges, resulting in an indeterminable number of critical attack vectors, allowing remote attackers to request server-side resources or potentially execute arbitrary code through various SSRF techniques.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-43ch-2h55-2vj7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-43ch-2h55-2vj7 -
github.com/advisories/GHSA-43ch-2h55-2vj7
CVEs related to QID 982003
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-43ch-2h55-2vj7 | private-ip |
|