The netmask package prior to 2.0.1 for Node.js mishandles certain unexpected characters in an IP address string, such as an octal digit of 9. This (in some situations) allows malicious users to bypass access control that is based on IP addresses. NOTE: this issue exists because of an incomplete fix for CVE-2021-28918.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
netmask project netmask |