Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade org.webjars.npm:ip-address to version 10.7.2 or higher.
org.webjars.npm:ip-address is an A library for parsing IPv4 and IPv6 IP addresses in node and the browser.
Affected versions of this package are vulnerable to Improper Validation of Specified Type of Input via isHostInSubnet() (and isInSubnet() which delegates to it), which compares masked binary strings without first verifying that both addresses belong to the same address family. Because Address4 pads its binary representation to 32 bits and Address6 pads to 128 bits, leading bit sequences can coincide across families, causing an IPv6 address to be incorrectly reported as contained within an IPv4 subnet and vice versa (for example, a00::1 is evaluated as inside 10.0.0.0/8). An attacker who controls an IP address value passed to a subnet membership check can bypass trust-boundary decisions such as SSRF allow/deny filters by supplying an address of the opposite family.