Server-Side Request Forgery in Node.js ip-utils Package Through 2.4.0
The ip-utils package for Node.js through version 2.4.0 contains a potential server-side request forgery (SSRF) vulnerability. The issue stems from incorrect IP address categorization, where certain IP addresses like 0x7f.1 are incorrectly identified as globally routable due to a falsy return value from the isPrivate method. This misclassification could potentially allow an attacker to bypass IP address restrictions and make unauthorized requests.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
librasean ip-utils |