Node.js¸þ¤±¤Ë³«È¯¤µ¤ì¤Æ¤¤¤ëIP¥¢¥É¥ì¥¹´ÉÍý¥Ñ¥Ã¥±¡¼¥¸¡Önode-ip¡×¤ÎGitHub¥ê¥Ý¥¸¥È¥ê¤¬°ì»þŪ¤Ë¥¢¡¼¥«¥¤¥Ö¾õÂ֤ˤʤê¤Þ¤·¤¿¡£node-ip¤Î³«È¯¼Ô¤Ç¤¢¤ëFedor Indutny»á¤Ï¡¢¥¢¡¼¥«¥¤¥Ö¤ÎÍýͳ¤Ë¤Ä¤¤¤Æ¡Ö¸ØÄ¥¤µ¤ì¤¿Àȼå(¤¼¤¤¤¸¤ã¤¯)À­Êó¹ð¤Ë¤è¤Ã¤ÆÌ䤤¹ç¤ï¤»¤¬Â¿È¯¤·¤¿¤¿¤á¡×¤ÈÀâÌÀ¤·¤Æ¤¤¤Þ¤¹¡£



Dev rejects CVE severity, makes his GitHub repo read-only

https://www.bleepingcomputer.com/news/security/dev-rejects-cve-severity-makes-his-github-repo-read-only/

node-ip¤ÏNode.js¸þ¤±¤ÎIP¥¢¥É¥ì¥¹´ÉÍý¥Ñ¥Ã¥±¡¼¥¸¤Ç¤¹¡£node-ip¤Î¥Ñ¥Ã¥±¡¼¥¸¾ðÊó¤ò³Îǧ¤¹¤ë¤È¡¢1½µ´Ö¤Ë170Ëü²ó°Ê¾å¥À¥¦¥ó¥í¡¼¥É¤µ¤ì¤ë¿Íµ¤¥Ñ¥Ã¥±¡¼¥¸¤Ç¤¢¤ë¤³¤È¤¬Ê¬¤«¤ê¤Þ¤¹¡£



¤½¤ó¤Ênode-ip¤Ë¤Ä¤¤¤Æ¡¢2024ǯ2·î9Æü¤Ë¡Ö¥×¥é¥¤¥Ù¡¼¥ÈIP¥¢¥É¥ì¥¹¤ò¥Ñ¥Ö¥ê¥Ã¥¯¤ÊIP¥¢¥É¥ì¥¹¤È¤·¤Æ°·¤¦¤³¤È¤¬¤¢¤ë¡×¤È¤¤¤¦ÀȼåÀ­¤¬Â¸ºß¤¹¤ë¤³¤È¤¬Êó¹ð¤µ¤ì¤Þ¤·¤¿¡£Êó¹ð¤Ç¤Ï¡¢Åö³ºÀȼåÀ­¤ò°­ÍѤ¹¤ë¤ÈSSRF¹¶·â¤¬²Äǽ¤Ë¤Ê¤ë¤ÈÀâÌÀ¤µ¤ì¤Æ¤ª¤ê¡¢Êƹñ¹ñΩɸ½àµ»½Ñ¸¦µæ½ê(NIST)¤¬±¿±Ä¤¹¤ëÀȼåÀ­¥Ç¡¼¥¿¥Ù¡¼¥¹¤Î¡ÖNational Vulunerability Database(NVD)¡×¤Ë¤Ï¥¹¥³¥¢9.8¤ÎCritical(¶ÛµÞ)¤ÊÀȼåÀ­¤È¤·¤ÆÅÐÏ¿¤µ¤ì¤Æ¤¤¤Þ¤¹¡£¤Ê¤ª¡¢CVE¤Ï¡ÖCVE-2023-42282¡×¤Ç¤¹¡£



Åö³ºÀȼåÀ­¤ÏNVD¤ËÅÐÏ¿¤µ¤ì¤¿¸å¤ËGitHub¤ÎÀȼåÀ­¾ðÊó¤Þ¤È¤á¥Ú¡¼¥¸¡ÖGitHub Advisory Database¡×¤Ë¤â·ÇºÜ¤µ¤ì¤Þ¤·¤¿¡£



ÀȼåÀ­¤¬Êó¹ð¤µ¤ì¤¿¸å¡¢Indutny»á¤Ï2024ǯ2·î19Æü¤ËÌäÂê¤ò½¤Àµ¤·¤Þ¤·¤¿¡£¤·¤«¤·¡¢ÀȼåÀ­¤Î½¤Àµ¸å¤ânpm¤ÎÀȼåÀ­¥ì¥Ý¡¼¥È¥Ä¡¼¥ë¡Önpm-audit¡×¤ò¼Â¹Ô¤·¤¿¥æ¡¼¥¶¡¼¤«¤é¡Önode-ip¤ËÀȼåÀ­¤¬¤¢¤ë¡×¤È¤¤¤¦Êó¹ð¤¬ÂçÎ̤ËÆϤ­Â³¤±¤¿¤È¤Î¤³¤È¡£¤³¤Î¤¿¤á¡¢Indutny»á¤Ï2024ǯ6·î26Æü¤Ënode-ip¤ÎGitHub¥ê¥Ý¥¸¥È¥ê¤ò¥¢¡¼¥«¥¤¥Ö¤·¤Þ¤·¤¿¡£



Indutny»á¤ÏÀȼåÀ­¤Î¸ºß¼«ÂΤÏǧ¤á¤Ä¤Ä¡¢¡ÖÊó¹ð¤Ç¤Ï¡ØÀȼåÀ­¤ò°­ÍѤ¹¤ë¤³¤È¤ÇSSRF¹¶·â¤¬²Äǽ¤È¤Ê¤ë¡Ù¤È¤µ¤ì¤Æ¤¤¤ë¤¬¡¢¤½¤Î¤è¤¦¤Ê¥»¥­¥å¥ê¥Æ¥£¥ê¥¹¥¯¤¬¤¢¤ë¤È¤Ï¹Í¤¨¤é¤ì¤Ê¤¤¡×¤È¼çÄ¥¤·¡¢¥¢¡¼¥«¥¤¥Ö¤ÈƱÆü¤ËÀȼåÀ­¤Î¥ê¥¹¥¯¤Î¸«Ä¾¤·¤òµá¤á¤Þ¤·¤¿¡£



¤½¤Î·ë²Ì¡¢GitHub Advisory Database¾å¤Ç¤ÏÀȼåÀ­¥ì¥Ù¥ë¤¬Law(Äã)¤Ë°ú¤­²¼¤²¤é¤ì¤Þ¤·¤¿¡£¤Þ¤¿¡¢Indutny»á¤Ï¡Ö¥×¥é¥¤¥Ù¡¼¥ÈÀȼåÀ­¥ì¥Ý¡¼¥È¤ò¹½À®¤¹¤ë¤³¤È¤Ç¡¢ÀȼåÀ­¾ðÊ󤬹­¤¯¸ø³«¤µ¤ì¤ëÁ°¤Ë¥×¥é¥¤¥Ù¡¼¥È¤ÊÄÌÃΤò¼õ¤±¤ë¤³¤È¤¬¤Ç¤­¤ë¡×¤È¤¤¤¦¥¢¥É¥Ð¥¤¥¹¤âÆÀ¤Þ¤·¤¿¡£



Indutny»á¤ÏGitHub¾å¤Ç¤Î¥»¥­¥å¥ê¥Æ¥£¥ê¥¹¥¯¤Î½¤Àµ¤ò¼õ¤±¤Æ¡¢node-ip¤Î¥¢¡¼¥«¥¤¥Ö¤ò²ò½ü¤·¤Þ¤·¤¿¡£¤¿¤À¤·¡¢NVD¾å¤Ë¤Ï¶ÛµÞ¤Î¥ê¥¹¥¯¤òȼ¤¦ÀȼåÀ­¤È¤·¤Æ»Ä¤ê³¤±¤Æ¤¤¤Þ¤¹¡£



³¤³°¥á¥Ç¥£¥¢¤ÎBleepingComputer¤ÏIndutny»á¤¬´¬¤­¹þ¤Þ¤ì¤¿»öÎã¤òƧ¤Þ¤¨¤Æ¡¢¡ÖÀȼåÀ­¤ÎÊó¹ð¤Î¿¤¯¤ÏÀÕǤ´¶¤Î¤¢¤ë¥»¥­¥å¥ê¥Æ¥£¸¦µæ¼Ô¤Ë¤è¤Ã¤Æ¹Ô¤ï¤ì¤ë¤¬¡¢Ãæ¤Ë¤Ï¡Ø½ÅÂç¤ÊÀȼåÀ­¤ò¸«¤Ä¤±¤¿¡Ù¤È¤¤¤¦·ÐÎò¤òºî¤ë¤¿¤á¤ËÂ礲¤µ¤ËÊó¹ð¤¹¤ë¸¦µæ¼Ô¤â¸ºß¤¹¤ë¡×¤È»ØŦ¤·¤Æ¤¤¤Þ¤¹¡£

¤Ê¤ª¡¢²áµî¤Ë¤Ï¥Ç¡¼¥¿Å¾Á÷¥Ä¡¼¥ë¤ÎcURL¤Ç¤â¡Ö¥ê¥¹¥¯¤Î¾®¤µ¤¤ÀȼåÀ­¤Ê¤Î¤Ë¡¢½ÅÂç¤ÊÀȼåÀ­¤È¤·¤ÆÊó¹ð¤µ¤ì¤ë¡×¤È¤¤¤¦»ö¾Ý¤¬È¯À¸¤·¤Æ³«È¯¼Ô¤¬¶ì¸À¤òÄ褷¤Æ¤¤¤Þ¤¹¡£

ÀȼåÀ­¤ËID¤ò³ä¤ê¿¶¤Ã¤Æ´ÉÍý¤¹¤ë¡ÖCVE¡×¤Î¥·¥¹¥Æ¥à¤Ë¤Ï·ç´Ù¤¬¤¢¤ë¤È¤¤¤¦»ØŦ - GIGAZINE