CVE-2024-28607
LOW EPSS 3.8%
Published Mar 11, 20251y ago · Modified Jun 17, 20261w ago
2.9 CVSS 3.1
Published Mar 11, 2025 1y ago
Last Modified Jun 17, 2026 1w ago
Description
The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via a falsy isPrivate return value.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector Local
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Low
Availability None
Threat Intelligence
EPSS Exploit Probability
3.8% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-180
References 2
- gist.github.com https://gist.github.com/aydinnyunus/4d71e7d9a433f3afc658724b903f4d23
- github.com https://github.com/librasean/IP-Utils/blob/4f88799f94f21efe6ea9135129ab2bbeb0c58edc/src/IsPrivate.ts#L4
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.