nodejs-ip: arbitrary code execution via the isPublic() function
Published Feb 8, 2024
9.8
CRITICALCVSS 3.1
EPSS 1.61%
Description
The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.
Affected products
No data.
- < 1.1.9
- 2.0.0
No data.
HawtIO 4.0.0 for Red Hat build of Apache Camel 4
n/a
Fixed · RHSA-2024:3550
Migration Toolkit for Virtualization 2.5
migration-toolkit-virtualization/mtv-console-plugin-rhel9:2.5.6-4
Fixed · RHBA-2024:1440
NETWORK-OBSERVABILITY-1.6.0-RHEL-9
network-observability/network-observability-cli-rhel9:v1.6.0-66
Fixed · RHSA-2024:3868
NETWORK-OBSERVABILITY-1.6.0-RHEL-9
network-observability/network-observability-console-plugin-rhel9:v1.6.0-66
Fixed · RHSA-2024:3868
NETWORK-OBSERVABILITY-1.6.0-RHEL-9
network-observability/network-observability-ebpf-agent-rhel9:v1.6.0-66
Fixed · RHSA-2024:3868
NETWORK-OBSERVABILITY-1.6.0-RHEL-9
network-observability/network-observability-flowlogs-pipeline-rhel9:v1.6.0-66
Fixed · RHSA-2024:3868
NETWORK-OBSERVABILITY-1.6.0-RHEL-9
network-observability/network-observability-operator-bundle:1.6.0-78
Fixed · RHSA-2024:3868
NETWORK-OBSERVABILITY-1.6.0-RHEL-9
network-observability/network-observability-rhel9-operator:v1.6.0-66
Fixed · RHSA-2024:3868
RHDH-1.1-RHEL-9
rhdh/rhdh-hub-rhel9:1.1-97
Fixed · RHEA-2024:1366
RHODF-4.15-RHEL-9
odf4/mcg-core-rhel9:v4.15.0-68
Fixed · RHSA-2024:1383
Red Hat OpenShift Dev Spaces 3 Containers
devspaces/code-rhel8:3.17-19
Fixed · RHSA-2024:10236
Logging Subsystem for Red Hat OpenShift
openshift-logging/kibana6-rhel8
Not affected
Node HealthCheck Operator
workload-availability/node-remediation-console-rhel8
Affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-main-rhel8
Out of support scope
Red Hat Advanced Cluster Security 4
advanced-cluster-security/rhacs-main-rhel8
Not affected
Red Hat Enterprise Linux 8
nodejs:16/nodejs
Not affected
Red Hat Enterprise Linux 8
nodejs:18/nodejs
Not affected
Red Hat Enterprise Linux 8
nodejs:20/nodejs
Not affected
Red Hat Enterprise Linux 9
nodejs
Not affected
Red Hat Enterprise Linux 9
nodejs:18/nodejs
Not affected
Red Hat Enterprise Linux 9
nodejs:20/nodejs
Not affected
Red Hat Software Collections
rh-nodejs14-nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| HawtIO 4.0.0 for Red Hat build of Apache Camel 4 | n/a | Fixed | RHSA-2024:3550 |
| Migration Toolkit for Virtualization 2.5 | migration-toolkit-virtualization/mtv-console-plugin-rhel9:2.5.6-4 | Fixed | RHBA-2024:1440 |
| NETWORK-OBSERVABILITY-1.6.0-RHEL-9 | network-observability/network-observability-cli-rhel9:v1.6.0-66 | Fixed | RHSA-2024:3868 |
| NETWORK-OBSERVABILITY-1.6.0-RHEL-9 | network-observability/network-observability-console-plugin-rhel9:v1.6.0-66 | Fixed | RHSA-2024:3868 |
| NETWORK-OBSERVABILITY-1.6.0-RHEL-9 | network-observability/network-observability-ebpf-agent-rhel9:v1.6.0-66 | Fixed | RHSA-2024:3868 |
| NETWORK-OBSERVABILITY-1.6.0-RHEL-9 | network-observability/network-observability-flowlogs-pipeline-rhel9:v1.6.0-66 | Fixed | RHSA-2024:3868 |
| NETWORK-OBSERVABILITY-1.6.0-RHEL-9 | network-observability/network-observability-operator-bundle:1.6.0-78 | Fixed | RHSA-2024:3868 |
| NETWORK-OBSERVABILITY-1.6.0-RHEL-9 | network-observability/network-observability-rhel9-operator:v1.6.0-66 | Fixed | RHSA-2024:3868 |
| RHDH-1.1-RHEL-9 | rhdh/rhdh-hub-rhel9:1.1-97 | Fixed | RHEA-2024:1366 |
| RHODF-4.15-RHEL-9 | odf4/mcg-core-rhel9:v4.15.0-68 | Fixed | RHSA-2024:1383 |
| Red Hat OpenShift Dev Spaces 3 Containers | devspaces/code-rhel8:3.17-19 | Fixed | RHSA-2024:10236 |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/kibana6-rhel8 | Not affected | n/a |
| Node HealthCheck Operator | workload-availability/node-remediation-console-rhel8 | Affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-main-rhel8 | Out of support scope | n/a |
| Red Hat Advanced Cluster Security 4 | advanced-cluster-security/rhacs-main-rhel8 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:16/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:18/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 8 | nodejs:20/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs:18/nodejs | Not affected | n/a |
| Red Hat Enterprise Linux 9 | nodejs:20/nodejs | Not affected | n/a |
| Red Hat Software Collections | rh-nodejs14-nodejs | Not affected | n/a |
ip
npm
Introduced 2.0.0 Fixed 2.0.1ip
npm
Introduced 0 Fixed 1.1.9
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | ip | 2.0.0 | 2.0.1 |
| npm | ip | 0 | 1.1.9 |
Remediation
Red Hat statement
It appears that npm does not utilize the bundled code therefore Red Hat Enterprise Linux is not affected by this vulnerability. While the vulnerability in the NPM IP Package presents a significant security concern, it's categorized as important rather than critical due to several factors. Firstly, the misclassification of the private IP address 0x7f.1 as public by the isPublic() function does not directly lead to remote code execution or unauthorized access to critical systems. Instead, it facilitates SSRF attacks, which typically require additional conditions to fully exploit, such as the ability to influence server-side requests and responses. Additionally, the impact of SSRF attacks can vary depending on the specific environment and configuration of the affected system. While SSRF attacks can potentially lead to data exposure, service disruption, or lateral movement within a network, their severity is often mitigated by factors such as network segmentation, access controls, and the availability of sensitive resources. Red Hat Developer Hub contains a fix in 1.1-91 version.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (15)
- https://access.redhat.com/security/cve/CVE-2023-42282 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2265161 Issue Tracking
- https://cosmosofcyberspace.github.io/npm_ip_cve/npm_ip_cve.html ExploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-0552 Advisory
- https://github.com/JoshGlazebrook/socks/issues/93#issue-2128357447
- https://github.com/advisories/GHSA-78xj-cgh5-2h22 Advisory
- https://github.com/github/advisory-database/pull/3504#issuecomment-1937179999
- https://github.com/indutny/node-ip/commit/32f468f1245574785ec080705737a579be1223aa
- https://github.com/indutny/node-ip/commit/6a3ada9b471b09d5f0f5be264911ab564bf67894 Patch
- https://github.com/indutny/node-ip/pull/138
- https://huntr.com/bounties/bfc3b23f-ddc0-4ee7-afab-223b07115ed3/ ExploitTechnical Description
- https://nvd.nist.gov/vuln/detail/CVE-2023-42282
- https://security.netapp.com/advisory/ntap-20240315-0008/ Third Party Advisory
- https://www.bleepingcomputer.com/news/security/dev-rejects-cve-severity-makes-his-github-repo-read-only/ Press/Media Coverage
- https://www.cve.org/CVERecord?id=CVE-2023-42282
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub