Description
The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p8p7-x288-28g6 | Server-Side Request Forgery in Request |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-02T12:30:24.515Z
Reserved: 2023-03-13T00:00:00.000Z
Link: CVE-2023-28155
No data.
Status : Modified
Published: 2023-03-16T15:15:11.107
Modified: 2024-11-21T07:54:30.183
Link: CVE-2023-28155
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA