Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36715
HistoryAug 15, 2022 - 10:21 a.m.

Server-Side Request Forgery (SSRF)

2022-08-1510:21:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
53
undici
ssrf
vulnerability
path parameter
remote attackers

0.002 Low

EPSS

Percentile

61.0%

undici is vulnerable to server-side request forgery. The library assumes that the hostname won’t change, when in actuality it can change because the specified path parameter is combined with the base URL, allowing remote attackers to cause SSRF attacks via sending a crafted request through the path parameter of undici.request.

CPENameOperatorVersion
undicile5.4.0
undicile5.8.1
undicile5.4.0
undicile5.8.1