Critical Flaw Found In Widely Used Netmask Open Source Module
ID: befc063d-ded8-59e4-8cd1-968c8b655cd1
STIX ID: report--befc063d-ded8-59e4-8cd1-968c8b655cd1
Feed Name: Security Ledger
Security researchers discovered that the netmask NPM library misparses IPv4 addresses containing octal notations, causing trusted/private and public IPs to be misclassified; this flaw (CVE-2021-28918) can enable SSRF, local/remote file inclusion and other attacks against applications that rely on netmask for IP filtering. Patches (v2.0.0 / v2.0.1) were released but few downloads indicate most dependent projects remain vulnerable, and researchers warn similar parsing issues may exist in other libraries and languages.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
