CVE-2023-42282

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 8, 2024
Updated: Jul 3, 2024
CWE ID 918

Summary

CVE-2023-42282 is a newly disclosed vulnerability affecting the ip package version before 1.1.9 in Node.js. This issue arises due to an incorrect categorization of certain IP addresses, including those labeled as "0x7f.1," as globally routable via the isPublic function. Consequently, an attacker could potentially exploit this vulnerability to perform Server-Side Request Forgery (SSRF) attacks. By crafting malicious requests, they could gain unauthorized access to internal resources of the affected system. To mitigate the risk, it is recommended that users upgrade to the latest version of the ip package as soon as possible.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share