2.0.2
13 years ago
4 years ago
Known vulnerabilities in the netmask package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for freeVulnerability | Vulnerable Version |
---|---|
netmask is a library to parse IPv4 CIDR blocks. Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF). It incorrectly evaluates individual IPv4 octets that contain octal strings as left-stripped integers, leading to an inordinate attack surface on hundreds of thousands of projects that rely on For example, a remote unauthenticated attacker can request local resources using input data NOTE: This vulnerability has also been identified as: CVE-2021-29418 How to fix Server-side Request Forgery (SSRF)? Upgrade | <2.0.1 |
netmask is a library to parse IPv4 CIDR blocks. Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF). It incorrectly evaluates individual IPv4 octets that contain octal strings as left-stripped integers, leading to an inordinate attack surface on hundreds of thousands of projects that rely on For example, a remote unauthenticated attacker can request local resources using input data NOTE: This vulnerability has also been identified as: CVE-2021-28918 How to fix Server-side Request Forgery (SSRF)? Upgrade | <2.0.1 |