You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Angular 9项目ip包SSRF漏洞修复求助:重写版本无效且无法升级

关于ip包isPublic函数SSRF漏洞的修复求助

我发现ip包中的isPublic函数存在SSRF不当分类漏洞。执行npm audit获取漏洞报告时,得到以下与ip包相关的漏洞信息:

ip  *
Severity: high
ip SSRF improper categorization in isPublic - https://github.com/advisories/GHSA-2p57-rm9w-gvfp
fix available via npm audit fix --force
Will install @angular-devkit/build-angular@18.0.4, which is a breaking change
node_modules/ip
dns-packet  <=5.2.4
Depends on vulnerable versions of ip
node_modules/dns-packet
multicast-dns  6.0.0 - 7.2.2
Depends on vulnerable versions of dns-packet
node_modules/multicast-dns
  bonjour  >=3.3.1
  Depends on vulnerable versions of multicast-dns
  node_modules/bonjour
socks  1.0.0 - 2.7.1
Depends on vulnerable versions of ip
node_modules/socks
socks-proxy-agent  1.0.1 - 4.0.2
Depends on vulnerable versions of socks
node_modules/socks-proxy-agent

我的项目环境如下:

  • Angular CLI: 9.1.13
  • Node: 22.2.0
  • OS: win32 x64

由于使用Angular 9.1.13版本,升级到Angular 18会导致破坏性变更,因此我尝试在package.json中通过overrides字段将ip包重写为2.0.1版本:

"overrides": {
  "webpack-dev-server":{ 
    "ip": "^2.0.1",
  },
  "dns-packet": {
    "ip": "^2.0.1"
  },
  "socks": {
    "ip": "^2.0.1"
  }
}

该操作已更新ip包,但漏洞仍未解决。因无法升级Angular版本,恳请有相关修复经验的人士提供帮助。

内容的提问来源于stack exchange,提问作者NIKITA NANOTE

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.22 07:47:21