Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade org.webjars.npm:ip-address to version 10.7.0 or higher.
org.webjars.npm:ip-address is an A library for parsing IPv4 and IPv6 IP addresses in node and the browser.
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via isPrivate() in src/ipv6.ts, which fails to classify addresses in the RFC 8215 NAT64 local-use range 64:ff9b:1::/48 as private. An attacker who knows or guesses the operator's NAT64 prefix can supply an address in this range that isPrivate() incorrectly reports as globally routable, bypassing any access controls that rely on that check to block internal traffic.
Note: This is only exploitable if the server's network runs a NAT64 translator on a prefix inside 64:ff9b:1::/48 and the attacker knows or can guess the prefix length.