This repository has been archived by the owner on Apr 8, 2024. It is now read-only.
CVE-2023-42282 (Critical) detected in ip-1.1.5.tgz #263
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2023-42282 - Critical Severity Vulnerability
[](https://www.npmjs.com/package/ip)
Library home page: https://registry.npmjs.org/ip/-/ip-1.1.5.tgz
Path to dependency file: /generic-oauth/package.json
Path to vulnerable library: /tmp/git/generic-oauth/node_modules/ip/package.json
Dependency Hierarchy:
Found in base branch: master
An issue in NPM IP Package v.1.1.8 and before allows an attacker to execute arbitrary code and obtain sensitive information via the isPublic() function.
Publish Date: 2024-02-08
URL: CVE-2023-42282
Base Score Metrics:
Type: Upgrade version
Origin: GHSA-78xj-cgh5-2h22
Release Date: 2024-02-08
Fix Resolution: ip - 1.1.9,2.0.1
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: