OSV 1.4.0 · github-reviewed · 修改于 2020-09-01 02:35
发布时间
2019-05-30 04:24
GitHub 审查时间
2019-05-30 04:23
NVD 发布时间
—
源文件
advisories/github-reviewed/2019/05/GHSA-p72p-rjr2-r439/GHSA-p72p-rjr2-r439.json
Versions of terriajs-serverprior to 2.7.4 are vulnerable to Server-Side Request Forgery (SSRF). If an attacker has access to a server whitelisted by the terriajs-server proxy or if the attacker is able to modify the DNS records of a domain whitelisted by the terriajs-server proxy, the attacker can use the terriajs-server proxy to access any HTTP-accessible resources that are accessible to the server, including private resources in the hosting environment.
Upgrade to version 2.7.4 or later.