Vulnerabilities/

SSRF & Credentials Leak

Severity:
High

Description

nuxt-api-party allows developers to proxy requests to an API without exposing credentials to the client. A previous vulnerability allowed an attacker to change the baseURL of the request, potentially leading to credentials being leaked or SSRF.

Recommendation

Update the nuxt-api-party package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
nuxt-api-party
Anything's wrong? Let us know Last updated on December 12, 2023

This issue is available in SmartScanner Professional

See Pricing