QID 982795
QID 982795: Nodejs (npm) Security Update for get-ip-range (GHSA-6q4w-3wp4-q5wf)
The get-ip-range package before 4.0.0 for Node.js is vulnerable to denial of service (DoS) if the range is untrusted input. An attacker could send a large range (such as 128.0.0.0/1) that causes resource exhaustion.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6q4w-3wp4-q5wf for updates pertaining to this vulnerability.
Vendor References
- GHSA-6q4w-3wp4-q5wf -
github.com/advisories/GHSA-6q4w-3wp4-q5wf
CVEs related to QID 982795
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6q4w-3wp4-q5wf | get-ip-range |
|