CVE-2024-28607 – Node.js Ip-utils SSRF

The following table lists the changes that have been made to the
CVE-2024-28607 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Mar. 11, 2025

    Action Type Old Value New Value
    Added Description The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via a falsy isPrivate return value.
    Added CVSS V3.1 AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
    Added CWE CWE-180
    Added Reference https://gist.github.com/aydinnyunus/4d71e7d9a433f3afc658724b903f4d23
    Added Reference https://github.com/librasean/IP-Utils/blob/4f88799f94f21efe6ea9135129ab2bbeb0c58edc/src/IsPrivate.ts#L4
Share the Post:

Related Posts