Skip to content

Input for scanning can be any CIDR blocks passed to nmap

Critical
cedricbonhomme published GHSA-mmpf-rw6c-67mm Nov 20, 2023

Package

testing/helpers.py

Affected versions

2.1.0

Patched versions

2.1.1

Description

Summary

Input for scanning can be any CIDR blocks passed to nmap. You can scan 0.0.0.0/0 or even local networks.

Details

No need for more details ;-)

PoC

Fill the form for scanning.

Impact

Fix

The commit 7b3e7ca fixes GHSA-mmpf-rw6c-67mm and GHSA-9fhc-f3mr-w6h6.
It's the same commit because the same security measure has been implemented (check of the user's input with a regular expression).

Severity

Critical

CVE ID

CVE-2023-48310

Weaknesses

No CWEs

Credits