Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33863
HistoryJan 24, 2022 - 6:14 a.m.

Server-Side Request Forgery (SSRF)

2022-01-2406:14:14
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
ssrf
server side request forgery
validation bypass
information disclosure

EPSS

0.002

Percentile

55.7%

@isomorphic-git/cors-proxy is vulnerable to server side request forgery. The attacks are possible because it does not validate the URL passed via the request from client before loading, allowing the attacker to send malicious request to get sensitive information at the server.

EPSS

0.002

Percentile

55.7%

Related for VERACODE:33863