Description
The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.
Remediation
References
https://hackerone.com/reports/891270
Related Vulnerabilities
CVE-2021-23337 Vulnerability in maven package org.webjars.npm:lodash.template
CVE-2019-15952 Vulnerability in npm package total.js
CVE-2022-24723 Vulnerability in npm package urijs
CVE-2020-7736 Vulnerability in npm package bmoor
CVE-2023-39013 Vulnerability in maven package no.priv.garshol.duke:duke