ProxyScotch is a simple proxy server created for hoppscotch.io. The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP request is made by a backend server to an untrusted URL submitted by a user. It leads to a leakage of sensitive information from the server.
{
"github_reviewed": true,
"severity": "HIGH",
"cwe_ids": [
"CWE-918"
],
"nvd_published_at": "2022-05-01T16:15:00Z",
"github_reviewed_at": "2022-05-04T20:14:02Z"
}