HIGH8.2
GHSA-x8rq-rc7x-5fg5
uppy's companion module is vulnerable to Server-Side Request Forgery (SSRF)
Quick fix
GHSA-x8rq-rc7x-5fg5 — @uppy/companion: upgrade to the fixed version with the command below.
npm install @uppy/companion@3.1.5Details
uppy's companion module is vulnerable to Server-Side Request Forgery (SSRF) via IPv4-mapped IPv6 addresses.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-0086[ADVISORY]
- https://github.com/transloadit/uppy/pull/3403[WEB]
- https://github.com/transloadit/uppy/commit/fc137e30a2a3102eb191141f280d5de20dacdf8f[WEB]
- https://github.com/transloadit/uppy[WEB]
- https://github.com/transloadit/uppy/releases/tag/uppy%402.3.3[WEB]
- https://huntr.dev/bounties/c1c03ef6-3f18-4976-a9ad-08c251279122[WEB]