Server-Side Request Forgery in @uppy/companion
High severity
GitHub Reviewed
Published
Aug 13, 2020
to the GitHub Advisory Database
•
Updated Sep 13, 2023
Package
Affected versions
< 1.13.2
>= 2.0.0-alpha.0, <= 2.0.0-alpha.4
Patched versions
1.13.2
2.0.0-alpha.5
Description
Reviewed
Aug 13, 2020
Published to the GitHub Advisory Database
Aug 13, 2020
Last updated
Sep 13, 2023
The @uppy/companion npm package before versions 1.13.2 and 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.
References