Skip to content

[GHSA-78xj-cgh5-2h22] NPM IP package vulnerable to Server-Side Request Forgery (SSRF) attacks#3553

Merged
advisory-database[bot] merged 1 commit intoiFreilicht/advisory-improvement-3553from
iFreilicht-GHSA-78xj-cgh5-2h22
Feb 20, 2024
Merged

[GHSA-78xj-cgh5-2h22] NPM IP package vulnerable to Server-Side Request Forgery (SSRF) attacks#3553
advisory-database[bot] merged 1 commit intoiFreilicht/advisory-improvement-3553from
iFreilicht-GHSA-78xj-cgh5-2h22

Conversation

@iFreilicht
Copy link

Updates

  • Affected products

Comments
A fix to the 1.x track was released in 1.1.9, see indutny/node-ip#138 (comment)

A fix to the 2.x track was released in 2.0.1, see indutny/node-ip#138 (comment)

Updating to 2.x from 1.x is in theory a breaking change, so I set the patched versions appropriately.

@github-actions github-actions bot changed the base branch from main to iFreilicht/advisory-improvement-3553 February 19, 2024 09:41
lsmith77 added a commit to witty-works/browser-extension that referenced this pull request Feb 20, 2024
@advisory-database advisory-database bot merged commit 4e9cd42 into iFreilicht/advisory-improvement-3553 Feb 20, 2024
@advisory-database
Copy link
Contributor

Hi @iFreilicht! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the iFreilicht-GHSA-78xj-cgh5-2h22 branch February 20, 2024 18:30
lsmith77 added a commit to witty-works/browser-extension that referenced this pull request Mar 5, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

Comments