First published: Mon May 27 2024(Updated: )
Node.js ip module is vulnerable to server-side request forgery, caused by a flaw with IP addresses are improperly categorized as globally routable via isPublic. By sending a specially crafted request, an attacker could exploit this vulnerability to conduct SSRF attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
npm/ip | <=2.0.1 | |
IBM Planning Analytics | <=2.1 | |
IBM Planning Analytics | <=2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29415 has been classified as a critical vulnerability due to the potential for server-side request forgery attacks.
To mitigate CVE-2024-29415, upgrade the 'ip' module to version 2.0.2 or higher, or update to a more recent version of affected products.
CVE-2024-29415 affects the 'ip' module (version 2.0.1 and below) and IBM Planning Analytics (version 2.1 and below).
An attacker can exploit CVE-2024-29415 to perform server-side request forgery (SSRF) attacks by sending specially crafted requests.
The 'ip' module related to CVE-2024-29415 is maintained by Indutny.