VDB
Sign up
HIGH7.5

GHSA-5hjh-c26m-xw8w

ProxyScotch is vulnerable to a server-side Request Forgery (SSRF)

Quick fix

GHSA-5hjh-c26m-xw8w — github.com/hoppscotch/proxyscotch: upgrade to the fixed version with the command below.

go get github.com/hoppscotch/proxyscotch@v1.0.0

Details

ProxyScotch is a simple proxy server created for hoppscotch.io. The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP request is made by a backend server to an untrusted URL submitted by a user. It leads to a leakage of sensitive information from the server.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hoppscotch/proxyscotch
Introduced in: 0Fixed in: 1.0.0
Fixgo get github.com/hoppscotch/proxyscotch@v1.0.0

References