Server-Side Request Forgery in Request #26

Closed
opened 2023-03-17 04:44:26 +00:00 by argoyle · 0 comments
argoyle commented 2023-03-17 04:44:26 +00:00 (Migrated from gitlab.com)

⚠️ dependabot-gitlab has detected security vulnerability for request in path: /, manifest_file: /package.json but was unable to update it! ⚠️

Package Severity Affected versions Patched versions IDs
request (NPM) MODERATE <= 2.88.2 GHSA-p8p7-x288-28g6,CVE-2023-28155

Description

The Request package through 2.88.2 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

References

⚠️ `dependabot-gitlab` has detected security vulnerability for `request` in path: `/`, manifest_file: `/package.json` but was unable to update it! ⚠️ * https://github.com/advisories/GHSA-p8p7-x288-28g6 | Package | Severity | Affected versions | Patched versions | IDs | |---------------|----------|-------------------|------------------|----------------------------------------| | request (NPM) | MODERATE | <= 2.88.2 | | `GHSA-p8p7-x288-28g6`,`CVE-2023-28155` | # Description The Request package through 2.88.2 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer. # References * https://nvd.nist.gov/vuln/detail/CVE-2023-28155 * https://github.com/request/request/issues/3442 * https://github.com/request/request/pull/3444 * https://doyensec.com/resources/Doyensec_Advisory_RequestSSRF_Q12023.pdf * https://github.com/advisories/GHSA-p8p7-x288-28g6
argoyle (Migrated from gitlab.com) closed this issue 2023-06-02 14:11:13 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: dancefinder/dancefinder-app#26