Server-Side Request Forgery in Request
Moderate severity
GitHub Reviewed
Published
Mar 16, 2023
to the GitHub Advisory Database
•
Updated Mar 21, 2024
Description
Published by the National Vulnerability Database
Mar 16, 2023
Published to the GitHub Advisory Database
Mar 16, 2023
Reviewed
Mar 16, 2023
Last updated
Mar 21, 2024
The
request
package through 2.88.2 for Node.js and the@cypress/request
package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).NOTE: The
request
package is no longer supported by the maintainer.References