Lucene search

K
osvGoogleOSV:GHSA-V82V-RQ72-PHQ9
HistoryJan 26, 2022 - 10:13 p.m.

Server side request forgery in @isomorphic-git/cors-proxy

2022-01-2622:13:05
Google
osv.dev
28
ssrf vulnerability
isomorphic git
cors-proxy

EPSS

0.002

Percentile

55.7%

The package @isomorphic-git/cors-proxy before 2.7.1 is vulnerable to Server-side Request Forgery (SSRF) due to missing sanitization and validation of the redirection action in middleware.js.

EPSS

0.002

Percentile

55.7%

Related for OSV:GHSA-V82V-RQ72-PHQ9