Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-42282
HistoryFeb 08, 2024 - 5:15 p.m.

Design/Logic Flaw

2024-02-0817:15:00
PRIOn knowledge base
www.prio-n.com
21
node.js
ip package
ssrf

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.9%

The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

CPENameOperatorVersion
iple1.1.8
ipeq2.0.0

9.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

35.9%