CVE-2021-28918: Netmask NPM Package – Server-Side Request Forgery

CVE-2021-28918: Netmask NPM Package - Server-Side Request Forgery-渗透云记 - 专注于网络安全与技术分享
CVE-2021-28918: Netmask NPM Package – Server-Side Request Forgery
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-28918: Netmask npm Package – Server-Side Request Forgery

漏洞描述

Netmask NPM Package is susceptible to server-side request forgery because of improper input validation of octal strings in netmask npm package. This allows unauthenticated remote attackers to perform indeterminate ssrf, remote file inclusion, and local file inclusion attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享