{"id":"GHSA-43ch-2h55-2vj7","summary":"Server-Side Request Forgery in private-ip","details":"Insufficient RegEx in private-ip npm package v1.0.5 and below insufficiently filters reserved IP ranges resulting in indeterminate SSRF. An attacker can perform a large range of requests to ARIN reserved IP ranges, resulting in an indeterminable number of critical attack vectors, allowing remote attackers to request server-side resources or potentially execute arbitrary code through various SSRF techniques.","aliases":["CVE-2020-28360"],"modified":"2023-11-08T04:03:25.257857Z","published":"2021-04-13T15:18:17Z","database_specific":{"nvd_published_at":"2020-11-23T21:15:00Z","cwe_ids":["CWE-918"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-03-29T21:49:55Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-28360"},{"type":"WEB","url":"https://github.com/frenchbread/private-ip/commit/840664c4b9ba7888c41cfee9666e9a593db133e9"},{"type":"WEB","url":"https://github.com/frenchbread/private-ip"},{"type":"WEB","url":"https://johnjhacking.com/blog/cve-2020-28360"},{"type":"WEB","url":"https://www.npmjs.com/package/private-ip"}],"affected":[{"package":{"name":"private-ip","ecosystem":"npm","purl":"pkg:npm/private-ip"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-43ch-2h55-2vj7/GHSA-43ch-2h55-2vj7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}