Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4c7m-wxvm-r7gc

Опубликовано: 14 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

Improper parsing of octal bytes in netmask

Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.

:exclamation: NOTE: The fix for this issue was incomplete. A subsequent fix was made in version 2.0.1 which was assigned CVE-2021-29418 / GHSA-pch5-whg9-qr2r. For complete protection from this vulnerability an upgrade to version 2.0.1 or later is recommended.

Пакеты

Наименование

netmask

npm
Затронутые версииВерсия исправления

< 1.1.0

1.1.0

EPSS

Процентиль: 99%
0.85896
Высокий

9.1 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.1
redhat
почти 5 лет назад

Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.

CVSS3: 9.1
nvd
почти 5 лет назад

Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.

EPSS

Процентиль: 99%
0.85896
Высокий

9.1 Critical

CVSS3

Дефекты

CWE-20