CVE-2023-28155
Summary
| CVE | CVE-2023-28155 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-16 15:15:00 UTC |
| Updated | 2023-11-07 04:10:00 UTC |
| Description | ** UNSUPPORTED WHEN ASSIGNED ** The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| doyensec.com/resources/Doyensec_Advisory_RequestSSRF_Q12023.pdf |
MISC |
doyensec.com |
|
| CVE-2023-28155 Node.js Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| Ssrf fix by SzymonDrosdzol · Pull Request #3444 · request/request · GitHub |
MISC |
github.com |
|
| CVE-2023-28155 Request allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect · Issue #3442 · request/request · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 906951 Common Base Linux Mariner (CBL-Mariner) Security Update for reaper (25664-1)
- 906985 Common Base Linux Mariner (CBL-Mariner) Security Update for nodejs (25641-1)