QID 997191
Date Published: 2024-02-12
QID 997191: NodeJs (Npm) Security Update for ip (GHSA-78xj-cgh5-2h22)
An issue in NPM IP Package v.1.1.8 and before allows an attacker to execute arbitrary code and obtain sensitive information via the isPublic() function. This can lead to potential Server-Side Request Forgery (SSRF) attacks. The core issue is the function's failure to accurately distinguish between public and private IP addresses.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-78xj-cgh5-2h22 for updates and patch information.
Vendor References
- GHSA-78xj-cgh5-2h22 -
github.com/advisories/GHSA-78xj-cgh5-2h22
CVEs related to QID 997191
Software Advisories
| Advisory ID | Software | Component | Link |
|---|