Lucene search

K
osvGoogleOSV:GHSA-4C7M-WXVM-R7GC
HistoryApr 14, 2021 - 3:03 p.m.

Improper parsing of octal bytes in netmask

2021-04-1415:03:16
Google
osv.dev
34
netmask parsing vulnerability
octal bytes
input validation
unauthenticated attackers
remote attacks
ssrf
rfi
lfi
vulnerable packages
critical hosts
vpn
lan
incomplete fix
cve-2021-29418
ghsa-pch5-whg9-qr2r
upgrade recommendation

EPSS

0.08

Percentile

94.4%

Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.

:exclamation: NOTE: The fix for this issue was incomplete. A subsequent fix was made in version 2.0.1 which was assigned CVE-2021-29418 / GHSA-pch5-whg9-qr2r. For complete protection from this vulnerability an upgrade to version 2.0.1 or later is recommended.