VDB
Sign up
HIGH

GHSA-w789-49fc-v8hr

TerriaJS-Server has a domain validation bypass vulnerability in its proxy allowlist

Quick fix

GHSA-w789-49fc-v8hr — terriajs-server: upgrade to the fixed version with the command below.

npm install terriajs-server@4.0.3

Details

### Impact A validation bug allows an attacker to proxy domains not explicitly allowed in the `proxyableDomains` configuration.

The validation only checks if a hostname _ended_ with an allowed domain. This meant:

If `example.com` is allowed in `proxyableDomains`:

- ✅ example.com is allowed (correct) - ✅ api.example.com is allowed (correct) - ⚠️ maliciousexample.com is allowed (incorrect)

An attacker could register maliciousexample.com and proxy content through `terriajs-server`, bypassing proxy restrictions.

### Patches All versions up to 4.0.2 are affected. Upgrade to 4.0.3 to address the vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/terriajs-server
Introduced in: 0Fixed in: 4.0.3
Fixnpm install terriajs-server@4.0.3

References