Vulnerabilities/

Server side request forgery in @isomorphic-git/cors-proxy

Severity:
High

Description

The package @isomorphic-git/cors-proxy before 2.7.1 is vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization and validation of the redirection action in middleware.js.

Recommendation

Update the @isomorphic-git/cors-proxy package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@isomorphic-git/cors-proxy
Anything's wrong? Let us know Last updated on February 03, 2023

This issue is available in SmartScanner Professional

See Pricing