Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-28918

Опубликовано: 01 апр. 2021
Источник: nvd
CVSS3: 9.1
CVSS2: 6.4
EPSS Высокий

Описание

Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:netmask_project:netmask:*:*:*:*:*:node.js:*:*
Версия до 1.0.6 (включая)

EPSS

Процентиль: 99%
0.85896
Высокий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-704

Связанные уязвимости

CVSS3: 9.1
redhat
почти 5 лет назад

Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.

CVSS3: 9.1
github
почти 5 лет назад

Improper parsing of octal bytes in netmask

EPSS

Процентиль: 99%
0.85896
Высокий

9.1 Critical

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-704