CVE-2022-0086: uppy's companion module is vulnerable to Server-Side Request Forgery (SSRF)
(updated )
uppy’s companion module is vulnerable to Server-Side Request Forgery (SSRF) via IPv4-mapped IPv6 addresses.
References
- github.com/advisories/GHSA-x8rq-rc7x-5fg5
- github.com/transloadit/uppy
- github.com/transloadit/uppy/commit/fc137e30a2a3102eb191141f280d5de20dacdf8f
- github.com/transloadit/uppy/pull/3403
- github.com/transloadit/uppy/releases/tag/uppy%402.3.3
- huntr.dev/bounties/c1c03ef6-3f18-4976-a9ad-08c251279122
- nvd.nist.gov/vuln/detail/CVE-2022-0086
Code Behaviors & Features
Detect and mitigate CVE-2022-0086 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →