Описание
uppy's companion module is vulnerable to Server-Side Request Forgery (SSRF)
uppy's companion module is vulnerable to Server-Side Request Forgery (SSRF) via IPv4-mapped IPv6 addresses.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2022-0086
- https://github.com/transloadit/uppy/pull/3403
- https://github.com/transloadit/uppy/commit/fc137e30a2a3102eb191141f280d5de20dacdf8f
- https://github.com/transloadit/uppy
- https://github.com/transloadit/uppy/releases/tag/uppy%402.3.3
- https://huntr.dev/bounties/c1c03ef6-3f18-4976-a9ad-08c251279122
Пакеты
Наименование
@uppy/companion
npm
Затронутые версииВерсия исправления
< 3.1.5
3.1.5