VDB
Sign up
HIGH

GHSA-p72p-rjr2-r439

Server-Side Request Forgery in terriajs-server

Quick fix

GHSA-p72p-rjr2-r439 — terriajs-server: upgrade to the fixed version with the command below.

npm install terriajs-server@2.7.4

Details

Versions of `terriajs-server`prior to 2.7.4 are vulnerable to Server-Side Request Forgery (SSRF). If an attacker has access to a server whitelisted by the terriajs-server proxy or if the attacker is able to modify the DNS records of a domain whitelisted by the terriajs-server proxy, the attacker can use the terriajs-server proxy to access any HTTP-accessible resources that are accessible to the server, including private resources in the hosting environment.

## Recommendation

Upgrade to version 2.7.4 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/terriajs-server
Introduced in: 0Fixed in: 2.7.4
Fixnpm install terriajs-server@2.7.4

References