CVE-2024-29415

The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.
Configurations

No configuration.

History

17 Jan 2025, 20:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20250117-0010/ -

Information

Published : 2024-05-27 20:15

Updated : 2025-01-17 20:15


NVD link : CVE-2024-29415

Mitre link : CVE-2024-29415

CVE.ORG link : CVE-2024-29415


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)

CWE-941

Incorrectly Specified Destination in a Communication Channel