Intel

CVE-2024-29415

ip is vulnerable to SSRF

SSRF Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 27, 2024

81

High Risk

This Affects:

ip
Are you affected? Scan for Free

TL;DR

NPM ip packages confuses public and private IPs, might lead to SSRF.

Who does this affect?

You're running any version of 'ip' up to 2.0.1

Background info

ip is vulnerable to SSRF.

How to fix this

This package is no longer maintained. Users should look for ways to stop using this package. For example, the latest version of NPM library 'socks' does not use this library any more.