Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5hjh-c26m-xw8w

Опубликовано: 03 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

ProxyScotch is vulnerable to a server-side Request Forgery (SSRF)

ProxyScotch is a simple proxy server created for hoppscotch.io. The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP request is made by a backend server to an untrusted URL submitted by a user. It leads to a leakage of sensitive information from the server.

Пакеты

Наименование

github.com/hoppscotch/proxyscotch

go
Затронутые версииВерсия исправления

< 1.0.0

1.0.0

EPSS

Процентиль: 54%
0.00317
Низкий

7.5 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.5
nvd
почти 4 года назад

The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP request is made by a backend server to an untrusted URL submitted by a user. It leads to a leakage of sensitive information from the server.

EPSS

Процентиль: 54%
0.00317
Низкий

7.5 High

CVSS3

Дефекты

CWE-918