Improper input validation of octal strings in netmask npm package...
Vulnerability Description
Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attackers to perform indeterminate SSRF, RFI, and LFI attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-28918
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.npmjs.com/package/netmask
- https://github.com/rs/node-netmask
- https://www.bleepingcomputer.com/news/security/critical-netmask-networking-bug-impacts-thousands-of-applications/
- https://github.com/advisories/GHSA-pch5-whg9-qr2r
- https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-011.md
- https://security.netapp.com/advisory/ntap-20210528-0010/
- https://rootdaemon.com/2021/03/29/vulnerability-in-netmask-npm-package-affects-280000-projects/
Affected Vendor
netmask project
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.