VDB
Sign up
HIGH8.6

GHSA-v82v-rq72-phq9

Server side request forgery in @isomorphic-git/cors-proxy

Quick fix

GHSA-v82v-rq72-phq9 — @isomorphic-git/cors-proxy: upgrade to the fixed version with the command below.

npm install @isomorphic-git/cors-proxy@2.7.1

Details

The package @isomorphic-git/cors-proxy before 2.7.1 is vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization and validation of the redirection action in middleware.js.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@isomorphic-git/cors-proxy
Introduced in: 0Fixed in: 2.7.1
Fixnpm install @isomorphic-git/cors-proxy@2.7.1

References