{"id":99604,"date":"2021-03-29T10:22:51","date_gmt":"2021-03-29T08:22:51","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-npm-pakete-node-netmask-primenyaemom-v-270-tysyachah-proektah"},"modified":"2021-03-29T10:22:51","modified_gmt":"2021-03-29T08:22:51","slug":"uyazvimost-v-npm-pakete-node-netmask-primenyaemom-v-270-tysyachah-proektah","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-npm-pakete-node-netmask-primenyaemom-v-270-tysyachah-proektah","title":{"rendered":"Vuln\u00e9rabilit\u00e9 dans le paquet NPM node-netmask, utilis\u00e9e dans 270 000 projets","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Dans le paquet NPM node-netmask, qui compte environ 3 millions de t\u00e9l\u00e9chargements par semaine et est utilis\u00e9 comme d\u00e9pendance par plus de 270 000 projets sur GitHub, une vuln\u00e9rabilit\u00e9 (CVE-2021-28918) a \u00e9t\u00e9 identifi\u00e9e, permettant de contourner les v\u00e9rifications o\u00f9 le masque r\u00e9seau est utilis\u00e9 pour d\u00e9terminer l'appartenance \u00e0 des plages d'adresses ou pour le filtrage. Le probl\u00e8me a \u00e9t\u00e9 r\u00e9solu dans la version node-netmask 2.0.0.    <\/p>\n<p>La vuln\u00e9rabilit\u00e9 permet de traiter une adresse IP externe comme une adresse d'un r\u00e9seau interne et vice versa, et avec une certaine logique d'utilisation du module node-netmask dans l'application, de r\u00e9aliser des attaques SSRF (Server-side request forgery), RFI (Remote File Inclusion) et LFI (Local File Inclusion) pour acc\u00e9der aux ressources du r\u00e9seau interne et inclure dans la cha\u00eene d'ex\u00e9cution des fichiers externes ou locaux. Le probl\u00e8me r\u00e9side dans le fait que selon la sp\u00e9cification, les valeurs de cha\u00eene d'adresses commen\u00e7ant par z\u00e9ro doivent \u00eatre interpr\u00e9t\u00e9es comme des nombres octaux, mais le module \u00ab node-netmask \u00bb ne prend pas en compte cette particularit\u00e9 et les traite comme des nombres d\u00e9cimaux.       <\/p>\n<p>Par exemple, un attaquant peut demander une ressource locale en indiquant la valeur \u00ab 0177.0.0.1 \u00bb, qui correspond \u00e0 \u00ab 127.0.0.1 \u00bb, mais le module \u00ab node-netmask \u00bb va ignorer le z\u00e9ro et traiter \u00ab 0177.0.0.1 \u00bb comme \u00ab 177.0.0.1 \u00bb, ce qui dans l'application, lors de l'\u00e9valuation des r\u00e8gles d'acc\u00e8s, ne permettra pas de d\u00e9terminer l'identit\u00e9 avec \u00ab 127.0.0.1 \u00bb. De m\u00eame, un attaquant peut sp\u00e9cifier l'adresse \u00ab 0127.0.0.1 \u00bb, qui devrait \u00eatre identique \u00e0 \u00ab 87.0.0.1 \u00bb, mais dans le module \u00ab node-netmask \u00bb, elle sera trait\u00e9e comme \u00ab 127.0.0.1 \u00bb. On peut \u00e9galement contourner la v\u00e9rification des acc\u00e8s aux adresses intranet en indiquant des valeurs telles que \u00ab 012.0.0.1 \u00bb (\u00e9quivalent de \u00ab 10.0.0.1 \u00bb, mais lors de la v\u00e9rification, elle sera trait\u00e9e comme 12.0.0.1).     <\/p>\n<p>Les chercheurs ayant d\u00e9couvert le probl\u00e8me qualifient celui-ci de catastrophique et pr\u00e9sentent plusieurs sc\u00e9narios d'attaques, mais la plupart semblent th\u00e9oriques. Par exemple, il est question de la possibilit\u00e9 d'attaquer une application bas\u00e9e sur Node.js qui \u00e9tablit des connexions externes pour demander une ressource bas\u00e9e sur des param\u00e8tres ou des donn\u00e9es d'une requ\u00eate d'entr\u00e9e, mais aucune application sp\u00e9cifique n'est nomm\u00e9e ni d\u00e9taill\u00e9e. M\u00eame si l'on trouve des applications effectuant le chargement de ressources en fonction des donn\u00e9es fournies. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/fr\/lir\/ipv4\/\"   title=\"adresses IP\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"828\">adresses IP<\/a>, il n'est pas tout \u00e0 fait clair comment la vuln\u00e9rabilit\u00e9 peut \u00eatre appliqu\u00e9e pratiquement sans se connecter \u00e0 un r\u00e9seau local ou sans obtenir le contr\u00f4le des adresses IP \u00ab miroir \u00bb.     <\/p>\n<p>Les chercheurs supposent seulement que les propri\u00e9taires de 87.0.0.1 (Telecom Italia) et de 0177.0.0.1 (Brasil Telecom) ont la possibilit\u00e9 de contourner la restriction d'acc\u00e8s \u00e0 127.0.0.1. Un sc\u00e9nario plus r\u00e9aliste serait d'utiliser la vuln\u00e9rabilit\u00e9 pour contourner diverses listes de blocage mises en \u0153uvre c\u00f4t\u00e9 application. Le probl\u00e8me peut \u00e9galement \u00eatre appliqu\u00e9 pour \u00e9changer la d\u00e9finition de plages intranet dans le module NPM \u00ab private-ip \u00bb.<br \/>\n<br \/>Source : <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=54857\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 NPM-\u043f\u0430\u043a\u0435\u0442\u0435 node-netmask, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u043e\u043a\u043e\u043b\u043e 3 \u043c\u043b\u043d \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u0432 \u043d\u0435\u0434\u0435\u043b\u044e \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u043c \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438 \u0443 \u0431\u043e\u043b\u0435\u0435 270 \u0442\u044b\u0441\u044f\u0447 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432 \u043d\u0430 GitHub, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-28918), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438, \u0432 \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u0441\u0435\u0442\u0435\u0432\u0430\u044f \u043c\u0430\u0441\u043a\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u0442\u0441\u044f \u0434\u043b\u044f \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0435\u043d\u0438\u044f \u0432\u0445\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u0432 \u0434\u0438\u0430\u043f\u0430\u0437\u043e\u043d\u044b \u0430\u0434\u0440\u0435\u0441\u043e\u0432 \u0438\u043b\u0438 \u0434\u043b\u044f \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0435 node-netmask 2.0.0. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0434\u043e\u0431\u0438\u0442\u044c\u0441\u044f \u043e\u0431\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u0432\u043d\u0435\u0448\u043d\u0435\u0433\u043e IP-\u0430\u0434\u0440\u0435\u0441\u0430 \u043a\u0430\u043a [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-99604","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 NPM-\u043f\u0430\u043a\u0435\u0442\u0435 node-netmask, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u043e\u043a\u043e\u043b\u043e 3 \u043c\u043b\u043d \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u0432 \u043d\u0435\u0434\u0435\u043b\u044e \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u043c \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438 \u0443 \u0431\u043e\u043b\u0435\u0435 270 \u0442\u044b\u0441\u044f\u0447 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432 \u043d\u0430 GitHub, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-28918), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438, \u0432.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-npm-pakete-node-netmask-primenyaemom-v-270-tysyachah-proektah\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 NPM-\u043f\u0430\u043a\u0435\u0442\u0435 node-netmask, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432 270 \u0442\u044b\u0441\u044f\u0447\u0430\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u0430\u0445 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 NPM-\u043f\u0430\u043a\u0435\u0442\u0435 node-netmask, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u043e\u043a\u043e\u043b\u043e 3 \u043c\u043b\u043d \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u0432 \u043d\u0435\u0434\u0435\u043b\u044e \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u043c \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438 \u0443 \u0431\u043e\u043b\u0435\u0435 270 \u0442\u044b\u0441\u044f\u0447 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432 \u043d\u0430 GitHub, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-28918), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438, \u0432.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-npm-pakete-node-netmask-primenyaemom-v-270-tysyachah-proektah\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-03-29T08:22:51+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-03-29T08:22:51+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Vuln\u00e9rabilit\u00e9 dans le package NPM node-netmask, utilis\u00e9 dans 270 000 projets | ProHoster","description":"Dans le package NPM node-netmask, qui compte environ 3 millions de t\u00e9l\u00e9chargements par semaine et est utilis\u00e9 comme d\u00e9pendance par plus de 270 000 projets sur GitHub, une vuln\u00e9rabilit\u00e9 (CVE-2021-28918) a \u00e9t\u00e9 d\u00e9tect\u00e9e, permettant de contourner les v\u00e9rifications.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-npm-pakete-node-netmask-primenyaemom-v-270-tysyachah-proektah","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 NPM-\u043f\u0430\u043a\u0435\u0442\u0435 node-netmask, \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0432 270 \u0442\u044b\u0441\u044f\u0447\u0430\u0445 \u043f\u0440\u043e\u0435\u043a\u0442\u0430\u0445 | ProHoster","og:description":"\u0412 NPM-\u043f\u0430\u043a\u0435\u0442\u0435 node-netmask, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0435\u043c \u043e\u043a\u043e\u043b\u043e 3 \u043c\u043b\u043d \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a \u0432 \u043d\u0435\u0434\u0435\u043b\u044e \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u043e\u043c \u0432 \u043a\u0430\u0447\u0435\u0441\u0442\u0432\u0435 \u0437\u0430\u0432\u0438\u0441\u0438\u043c\u043e\u0441\u0442\u0438 \u0443 \u0431\u043e\u043b\u0435\u0435 270 \u0442\u044b\u0441\u044f\u0447 \u043f\u0440\u043e\u0435\u043a\u0442\u043e\u0432 \u043d\u0430 GitHub, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-28918), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u043e\u0431\u043e\u0439\u0442\u0438 \u043f\u0440\u043e\u0432\u0435\u0440\u043a\u0438, \u0432.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-v-npm-pakete-node-netmask-primenyaemom-v-270-tysyachah-proektah","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-03-29T08:22:51+00:00","article:modified_time":"2021-03-29T08:22:51+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"99604","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-29 08:24:48","updated":"2026-02-08 20:40:14","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/99604","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=99604"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/99604\/revisions"}],"predecessor-version":[{"id":158019,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/99604\/revisions\/158019"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=99604"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=99604"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=99604"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}