CVE-2024-28607
CVSS 3.1 Score 2.9 of 10 (low)
Details
Summary
CVE-2024-28607 is a vulnerability affecting the ip-utils package up to version 2.4.0 used in Node.js. This issue enables Server-Side Request Forgery (SSRF) attacks due to a misclassification of certain IP addresses as globally routable. The ip-utils package erroneously returns a falsely positive value for the isPrivate property for IPs like 0x7f.1, which should be considered private. Attackers can exploit this vulnerability to send malicious requests from the affected system to arbitrary internal servers or external resources, potentially leading to data leakage or unauthorized access. Users are advised to upgrade to the latest version of the ip-utils package to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Iputils
Affected Vendors
- Iputils