Описание
Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker can perform a large range of requests to ARIN reserved IP ranges, resulting in an indeterminable number of critical attack vectors, allowing remote attackers to request server-side resources or potentially execute arbitrary code through various SSRF techniques.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.5 (включая)
cpe:2.3:a:private-ip_project:private-ip:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 85%
0.02409
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-918
Связанные уязвимости
EPSS
Процентиль: 85%
0.02409
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-918