Lucene search

K
osvGoogleOSV:GHSA-PCH5-WHG9-QR2R
HistoryMar 29, 2021 - 9:32 p.m.

netmask npm package mishandles octal input data

2021-03-2921:32:05
Google
osv.dev
11
netmask package
node.js
mishandles
octal input data
ip addresses
access control
cve-2021-28918
security issue

EPSS

0.08

Percentile

94.4%

The netmask package before 2.0.1 for Node.js mishandles certain unexpected characters in an IP address string, such as an octal digit of 9. This (in some situations) allows attackers to bypass access control that is based on IP addresses. NOTE: this issue exists because of an incomplete fix for CVE-2021-28918.