Lucene search

K
osvGoogleOSV:CVE-2021-23664
HistoryJan 21, 2022 - 8:15 p.m.

CVE-2021-23664

2022-01-2120:15:08
Google
osv.dev
5
ssrf
server-side request forgery
middleware.js

EPSS

0.002

Percentile

55.7%

The package @isomorphic-git/cors-proxy before 2.7.1 are vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization and validation of the redirection action in middleware.js.

EPSS

0.002

Percentile

55.7%

Related for OSV:CVE-2021-23664