VDB
Sign up
MEDIUM6.1

GHSA-p8p7-x288-28g6

Server-Side Request Forgery in Request

Quick fix

GHSA-p8p7-x288-28g6 — @cypress/request: upgrade to the fixed version with the command below.

npm install @cypress/request@3.0.0

Details

The `request` package through 2.88.2 for Node.js and the `@cypress/request` package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).

NOTE: The `request` package is no longer supported by the maintainer.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/request
Introduced in: 0

No fixed version published yet for request (npm). Pin to a known-safe version or switch to an alternative.

npm/@cypress/request
Introduced in: 0Fixed in: 3.0.0
Fixnpm install @cypress/request@3.0.0

References