CVE-2024-28607 Information

Description

The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via a falsy isPrivate return value.

Reference

https://gist.github.com/aydinnyunus/4d71e7d9a433f3afc658724b903f4d23 https://github.com/librasean/IP-Utils/blob/4f88799f94f21efe6ea9135129ab2bbeb0c58edc/src/IsPrivate.ts#L4

Share on: