HIGH8.6
GHSA-v82v-rq72-phq9
Server side request forgery in @isomorphic-git/cors-proxy
Quick fix
GHSA-v82v-rq72-phq9 — @isomorphic-git/cors-proxy: upgrade to the fixed version with the command below.
npm install @isomorphic-git/cors-proxy@2.7.1Details
The package @isomorphic-git/cors-proxy before 2.7.1 is vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization and validation of the redirection action in middleware.js.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@isomorphic-git/cors-proxy
Introduced in:
0Fixed in: 2.7.1Fix
npm install @isomorphic-git/cors-proxy@2.7.1