HIGH7.5
GHSA-5hjh-c26m-xw8w
ProxyScotch is vulnerable to a server-side Request Forgery (SSRF)
Quick fix
GHSA-5hjh-c26m-xw8w — github.com/hoppscotch/proxyscotch: upgrade to the fixed version with the command below.
go get github.com/hoppscotch/proxyscotch@v1.0.0Details
ProxyScotch is a simple proxy server created for hoppscotch.io. The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP request is made by a backend server to an untrusted URL submitted by a user. It leads to a leakage of sensitive information from the server.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hoppscotch/proxyscotch
Introduced in:
0Fixed in: 1.0.0Fix
go get github.com/hoppscotch/proxyscotch@v1.0.0