QID 980555
QID 980555: Nodejs (npm) Security Update for @uppy/companion (GHSA-mm7r-265w-jv6f)
Versions of `@uppy/companion` prior to 1.9.3 are vulnerable to Server-Side Request Forgery (SSRF). The `get` route passes the user-controlled variable `req.body.url` to a GET request without sanitizing the value. This allows attackers to inject arbitrary URLs and make GET requests on behalf of the server.
## Recommendation
Upgrade to version 1.9.3 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mm7r-265w-jv6f for updates pertaining to this vulnerability.
Vendor References
- GHSA-mm7r-265w-jv6f -
github.com/advisories/GHSA-mm7r-265w-jv6f
CVEs related to QID 980555
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mm7r-265w-jv6f | @uppy/companion |
|