First published: Thu Feb 08 2024(Updated: )
An issue in NPM IP Package v.1.1.8 and before allows an attacker to execute arbitrary code and obtain sensitive information via the isPublic() function. <a href="https://cosmosofcyberspace.github.io/npm_ip_cve/npm_ip_cve.html">https://cosmosofcyberspace.github.io/npm_ip_cve/npm_ip_cve.html</a> <a href="https://github.com/indutny/node-ip">https://github.com/indutny/node-ip</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/node-ip | <=1.1.5-3<=1.1.5-5<=2.0.0+~1.1.0-1 | |
ubuntu/node-ip | <1.1.5-1ubuntu0.1~ | 1.1.5-1ubuntu0.1~ |
ubuntu/node-ip | <1.1.5-5ubuntu0.1~ | 1.1.5-5ubuntu0.1~ |
ubuntu/node-ip | <1.1.5+~1.1.0-1ubuntu0.1~ | 1.1.5+~1.1.0-1ubuntu0.1~ |
ubuntu/node-ip | <2.0.0+~1.1.0-1ubuntu0.1 | 2.0.0+~1.1.0-1ubuntu0.1 |
ubuntu/node-ip | <1.1.9<2.0.1 | 1.1.9 2.0.1 |
npm/ip | <1.1.9 | 1.1.9 |
npm/ip | =2.0.0 | 2.0.1 |
redhat/nodejs-ip | <1.1.9 | 1.1.9 |
redhat/nodejs-ip | <2.0.1 | 2.0.1 |
IBM Data Virtualization on Cloud Pak for Data | <=3.0 | |
IBM Watson Query with Cloud Pak for Data | <=2.2 | |
IBM Watson Query with Cloud Pak for Data | <=2.1 | |
IBM Watson Query with Cloud Pak for Data | <=2.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.8 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.7 | |
Node.js | <1.1.9 | |
Node.js | =2.0.0 | |
Node.js | <=1.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-42282 is classified as a high-severity vulnerability due to its potential to execute arbitrary code and access sensitive information.
To mitigate CVE-2023-42282, upgrade to node-ip version 1.1.9 or higher, or 2.0.1 for upstream packages.
CVE-2023-42282 affects the NPM IP package versions 1.1.8 and below, as well as various versions of node-ip on Debian and Ubuntu systems.
The isPublic() function in the NPM IP Package is the specific point of vulnerability in CVE-2023-42282.
Yes, IBM Cognos Analytics versions up to 12.0.3 and 11.2.4 FP3 are impacted by CVE-2023-42282.