Description
The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p8p7-x288-28g6 | Server-Side Request Forgery in Request |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T12:30:24.515Z
Reserved: 2023-03-13T00:00:00.000Z
Link: CVE-2023-28155
No data.
Status : Modified
Published: 2023-03-16T15:15:11.107
Modified: 2024-11-21T07:54:30.183
Link: CVE-2023-28155
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA