Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29863
HistoryMar 31, 2021 - 12:33 a.m.

Server-Side Request Forgery (SSRF)

2021-03-3100:33:39
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
38
netmask
vulnerability
ssrf
ip addresses
exploitation
remote inclusion

EPSS

0.08

Percentile

94.4%

netmask is vulnerable to server-side request forgery (SSRF). The package is not able to differentiate private IP addresses as external IP addresses, and would allow an attacker to trick the application into parsing an IP address incorrectly. Successful exploitation of the vulnerability depends on how the package is used and possible attacks include server-side request forgery (SSRF) and remote/local file inclusion.