Skip to content

Server-Side Request Forgery in Request #180

@marcelomachado

Description

@marcelomachado

The Request package through 2.88.2 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer. See https://github.com/IBM/tpf-conceptnet-datasource/security/dependabot/10 .

This package is required by the @ldf/core 3.2.1 submodule.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions