CVE-2023-42282: SSRF
An issue in NPM IP Package v.1.1.8 and before allows an attacker to execute arbitrary code and obtain sensitive information via the isPublic() function. https://cosmosofcyberspace.github.io/npm_ip_cve/npm_ip_cve.html https://github.com/indutny/node-ip
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-42282?
CVE-2023-42282 is classified as a high-severity vulnerability due to its potential to execute arbitrary code and access sensitive information.
How do I fix CVE-2023-42282?
To mitigate CVE-2023-42282, upgrade to node-ip version 1.1.9 or higher, or 2.0.1 for upstream packages.
Which software packages are affected by CVE-2023-42282?
CVE-2023-42282 affects the NPM IP package versions 1.1.8 and below, as well as various versions of node-ip on Debian and Ubuntu systems.
What specific function in the NPM IP Package is vulnerable in CVE-2023-42282?
The isPublic() function in the NPM IP Package is the specific point of vulnerability in CVE-2023-42282.
Are there any notable products impacted by CVE-2023-42282?
Yes, IBM Cognos Analytics versions up to 12.0.3 and 11.2.4 FP3 are impacted by CVE-2023-42282.