Vulnerabilities/

Server-Side Request Forgery in Request

Severity:
Medium

Description

The request package through 2.88.2 for Node.js and the @cypress/request package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).

NOTE: The request package is no longer supported by the maintainer.

Recommendation

Update the @cypress/request package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@cypress/request
Anything's wrong? Let us know Last updated on March 21, 2024

This issue is available in SmartScanner Professional

See Pricing