The Request package through 2.88.2 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
⚠️ `dependabot-gitlab` has detected security vulnerability for `request` in path: `/`, manifest_file: `/package.json` but was unable to update it! ⚠️
* https://github.com/advisories/GHSA-p8p7-x288-28g6
| Package | Severity | Affected versions | Patched versions | IDs |
|---------------|----------|-------------------|------------------|----------------------------------------|
| request (NPM) | MODERATE | <= 2.88.2 | | `GHSA-p8p7-x288-28g6`,`CVE-2023-28155` |
# Description
The Request package through 2.88.2 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
# References
* https://nvd.nist.gov/vuln/detail/CVE-2023-28155
* https://github.com/request/request/issues/3442
* https://github.com/request/request/pull/3444
* https://doyensec.com/resources/Doyensec_Advisory_RequestSSRF_Q12023.pdf
* https://github.com/advisories/GHSA-p8p7-x288-28g6
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
⚠️
dependabot-gitlabhas detected security vulnerability forrequestin path:/, manifest_file:/package.jsonbut was unable to update it! ⚠️GHSA-p8p7-x288-28g6,CVE-2023-28155Description
The Request package through 2.88.2 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
References