Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FOSSA] Issue with netmask - VULNERABILITY #1

Open
pb-own opened this issue Mar 16, 2022 · 0 comments
Open

[FOSSA] Issue with netmask - VULNERABILITY #1

pb-own opened this issue Mar 16, 2022 · 0 comments

Comments

@pb-own
Copy link

pb-own commented Mar 16, 2022

VULNERABILITY - netmask (1.0.6)

View issue on FOSSA

Component URL

https://www.npmjs.com/package/netmask

Affected Projects

Issue

Vulnerability - CVE-2021-28918

Severity:
Critical (9.1)

Description:
Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.

Remediation:
Upgrade to version 2.0.1

Vulnerability - CVE-2021-29418

Severity:
Medium (5.3)

Description:
The netmask package before 2.0.1 for Node.js mishandles certain unexpected characters in an IP address string, such as an octal digit of 9. This (in some situations) allows attackers to bypass access control that is based on IP addresses. NOTE: this issue exists because of an incomplete fix for CVE-2021-28918.

Remediation:
Upgrade to version 2.0.1


Generated by FOSSA on 03/16/2022
Reported by FOSSA user: pbelton
Reported Issue: https://app.fossa.com/projects/git%2Bgithub.com%2FeGain%2Fegain-conversation-hub-sentiment-analysis/refs/branch/main/1b651e9e88259a0085a54d006099c41033e8e5c8/issues/security/796681?revisionScanId=11858268&status=any

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant