Executive brief
The 'ip' library for Node.js, which is used by developers to manage and validate network addresses, contains a flaw in how it identifies private versus public internet addresses. An attacker can use specially formatted IP addresses (such as those using octal or shorthand notation) to trick an application into treating a restricted internal server as a public one. This could allow an attacker to bypass security controls and access sensitive internal data or services that should not be reachable from the internet.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the 'ip' package through version 2.0.1 for Node.js due to improper input validation in the 'isPublic' function. The library fails to correctly identify certain IP address formats—including octal representations (e.g., 01200034567), shorthand IPv4 (e.g., 127.1), and specific IPv6-mapped formats—as private or loopback addresses, instead categorizing them as globally routable. This is an incomplete fix for CVE-2023-42282. An attacker can exploit this by providing these ambiguous formats to bypass SSRF protections that rely on 'isPublic' to block internal network access. While the vulnerability is network-reachable, successful exploitation depends on the application's specific use of the library to filter requests.
Affected products
- indutny ip <= 2.0.1
Timeline
- 2024-05-27: disclosed: NVD published the CVE record.
- 2024-06-02: advisory: GitHub published the security advisory.