OSV 1.4.0 · github-reviewed · 修改于 2020-09-01 03:01
发布时间
2020-09-03 23:51
GitHub 审查时间
2020-09-01 03:01
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-mm7r-265w-jv6f/GHSA-mm7r-265w-jv6f.json
Versions of @uppy/companion prior to 1.9.3 are vulnerable to Server-Side Request Forgery (SSRF). The get route passes the user-controlled variable req.body.url to a GET request without sanitizing the value. This allows attackers to inject arbitrary URLs and make GET requests on behalf of the server.
Upgrade to version 1.9.3 or later.