漏洞描述
Netmask NPM Package is susceptible to server-side request forgery because of improper input validation of octal strings in netmask npm package. This allows unauthenticated remote attackers to perform indeterminate SSRF, remote file inclusion, and local file inclusion attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
github.comhttps://github.com/sickcodes/security/blob/master/advisories/SICK-2021-011.md↗github.comhttps://github.com/advisories/GHSA-pch5-whg9-qr2r↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-28918↗github.comhttps://github.com/rs/node-netmask↗rootdaemon.comhttps://rootdaemon.com/2021/03/29/vulnerability-in-netmask-npm-package-affects-280000-projects/↗