Description
The package ssrf-agent before 1.0.5 are vulnerable to Server-side Request Forgery (SSRF) via the defaultIpChecker function. It fails to properly validate if the IP requested is private.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2458 | The package ssrf-agent before 1.0.5 are vulnerable to Server-side Request Forgery (SSRF) via the defaultIpChecker function. It fails to properly validate if the IP requested is private. |
Github GHSA |
GHSA-6gww-qpm6-mc2g | Server-Side Request Forgery in ssrf-agent |
References
History
No history.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-09-16T19:09:26.902Z
Reserved: 2021-01-08T00:00:00.000Z
Link: CVE-2021-23718
No data.
Status : Modified
Published: 2021-11-22T17:15:08.490
Modified: 2024-11-21T05:51:52.360
Link: CVE-2021-23718
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA