Executive brief
The netmask npm package, a widely-used library for parsing and validating IP addresses and network ranges (used by roughly 270,000 projects), improperly validates octal-formatted IP address strings. An attacker can craft malicious IP addresses that bypass IP-based access controls, potentially reaching internal VPN or LAN hosts that should be restricted. This affects any application using netmask for IP filtering or validation without upgrading to version 2.0.1 or later.
Technical details
The vulnerability is an improper input validation flaw (CWE-20) in the netmask npm package's octal byte parsing logic. The package uses JavaScript's parseInt() function to parse IP address octets, which interprets strings with leading zeros as octal values; however, the parsing is incomplete and allows invalid octal digits (e.g., "9" in octal notation) to bypass validation. An attacker can craft an IP address string like "127.0.0.9" or similar malformed octal notation that the package incorrectly parses, causing it to return a different IP than intended, thus bypassing IP-based access control lists. The attack requires no authentication or user interaction and is exploitable over the network by any remote party that can send an IP address string to an application using netmask. The initial fix in version 1.1.0 was incomplete; a subsequent complete fix was released in version 2.0.1 (CVE-2021-29418 / GHSA-pch5-whg9-qr2r), which removed reliance on parseInt() and added stricter validation.
Affected products
- netmask netmask <=2.0.0
CVE identifiers
- CVE-2021-29418
- CVE-2021-28918
Timeline
- 2021-04-01: disclosed: Initial disclosure via NVD for CVE-2021-28918
- 2021-03-18: patched: Incomplete fix released in version 1.1.0
- 2021-03-29: patched: Complete fix released in version 2.0.1 for CVE-2021-29418
- 2021-04-14: advisory: GHSA advisory published
References
- https://github.com/rs/node-netmask
- https://github.com/rs/node-netmask/blob/98294cb20695f2c6c36219a4fbcd4744fb8d0682/CHANGELOG.md
- https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-011.md
- https://rootdaemon.com/2021/03/29/vulnerability-in-netmask-npm-package-affects-280000-projects
- https://security.netapp.com/advisory/ntap-20210528-0010