GHSA-p8p7-x288-28g6

Suggest an improvement
Source
https://github.com/advisories/GHSA-p8p7-x288-28g6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-p8p7-x288-28g6/GHSA-p8p7-x288-28g6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p8p7-x288-28g6
Aliases
Related
Published
2023-03-16T15:30:19Z
Modified
2024-03-21T17:47:20Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Server-Side Request Forgery in Request
Details

The request package through 2.88.2 for Node.js and the @cypress/request package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).

NOTE: The request package is no longer supported by the maintainer.

References

Affected packages

npm / request

Package

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.88.2

npm / @cypress/request

Package

Name
@cypress/request
View open source insights on deps.dev
Purl
pkg:npm/%40cypress/request

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.0.0

Database specific

{
    "last_known_affected_version_range": "<= 2.88.12"
}