Skip to content

Dependabot: ip SSRF improper categorization in isPublic #255

Open
@tlindsay42

Description

@tlindsay42

Package: ip (npm)
Affected versions: <= 2.0.1
Patched version: None

Locations:

Dependabot couldn't auto-generate a ticket for this, so manually creating.

The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.

Metadata

Metadata

Assignees

No one assigned

    Labels

    dependenciesPull requests that update a dependency file

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions