Back

CRITICAL

nodejs-ip: arbitrary code execution via the isPublic() function

Published Feb 8, 2024

Description

The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

Affected products

Remediation

Red Hat statement

It appears that npm does not utilize the bundled code therefore Red Hat Enterprise Linux is not affected by this vulnerability. While the vulnerability in the NPM IP Package presents a significant security concern, it's categorized as important rather than critical due to several factors. Firstly, the misclassification of the private IP address 0x7f.1 as public by the isPublic() function does not directly lead to remote code execution or unauthorized access to critical systems. Instead, it facilitates SSRF attacks, which typically require additional conditions to fully exploit, such as the ability to influence server-side requests and responses. Additionally, the impact of SSRF attacks can vary depending on the specific environment and configuration of the affected system. While SSRF attacks can potentially lead to data exposure, service disruption, or lateral movement within a network, their severity is often mitigated by factors such as network segmentation, access controls, and the availability of sensitive resources. Red Hat Developer Hub contains a fix in 1.1-91 version.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (15)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner mitre
Published Feb 8, 2024
Updated May 15, 2025
Reserved Sep 8, 2023

CISA Vulnrichment

Updated May 8, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

Severity Important
Public date Feb 8, 2024
Bugzilla 2265161

ENISA EUVD

Assigner mitre
Published Feb 8, 2024
Updated May 15, 2025