Description
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.
Remediation
References
https://hackerone.com/reports/786956
Related Vulnerabilities
CVE-2022-23221 Vulnerability in maven package com.h2database:h2
CVE-2022-45387 Vulnerability in maven package org.jenkins-ci.plugins:bart
CVE-2018-3731 Vulnerability in npm package public
CVE-2020-7772 Vulnerability in npm package doc-path
CVE-2020-28052 Vulnerability in maven package bouncycastle:bcprov-jdk14