CVE-2021-28918

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-28918
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-28918.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-28918
Aliases
Related
Published
2021-04-01T13:15:14Z
Modified
2025-07-01T12:17:03.007068Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.

References

Affected packages

Git / github.com/rs/node-netmask

Affected ranges

Type
GIT
Repo
https://github.com/rs/node-netmask
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

0.*

0.0.0
0.0.1
0.0.2

1.*

1.0.5
1.0.6