flamencist / flamencist/CopyCssSelector

CVE-2023-28155 (Medium) detected in request-2.88.2.tgz

Open
#38 0 comments 0 reactions 0 assignees View on GitHub
Mend: dependency security vulnerability
Dominant language
JavaScript
Stars
28
Forks
3
PR merge metrics
No merged PRs in 30d

Description

## CVE-2023-28155 - Medium Severity Vulnerability
Vulnerable Library - request-2.88.2.tgz

Simplified HTTP request client.


Library home page: https://registry.npmjs.org/request/-/request-2.88.2.tgz


Path to dependency file: /package.json


Path to vulnerable library: /node_modules/request/package.json


Dependency Hierarchy:
- phantomjs-prebuilt-2.1.16.tgz (Root Library)
- :x: **request-2.88.2.tgz** (Vulnerable Library)


Vulnerability Details



** UNSUPPORTED WHEN ASSIGNED ** The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Publish Date: 2023-03-16

URL: CVE-2023-28155



CVSS 3 Score Details (5.5)

Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High


For more information on CVSS3 Scores, click here.

***
Step up your Open Source Security Game with Mend [here](https://www.whitesourcesoftware.com/full_solution_bolt_github)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.