CVE-2024-28607

LOW EPSS 3.8%
Published Mar 11, 20251y ago · Modified Jun 17, 20261w ago
2.9 CVSS 3.1
Low
Find Similar
Published Mar 11, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

The ip-utils package through 2.4.0 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via a falsy isPrivate return value.

CVSS Details

Base Score
2.9
Exploitability
1.4
Impact
1.4
Vector string
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector Local
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Low
Availability None

Threat Intelligence

EPSS Exploit Probability
3.8% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-180

References 2

  • gist.github.com https://gist.github.com/aydinnyunus/4d71e7d9a433f3afc658724b903f4d23
  • github.com https://github.com/librasean/IP-Utils/blob/4f88799f94f21efe6ea9135129ab2bbeb0c58edc/src/IsPrivate.ts#L4

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.