Description
The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.
Remediation
References
https://hackerone.com/reports/891270
Related Vulnerabilities
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:sort-connector-mysql-cdc
CVE-2018-14042 Vulnerability in maven package org.webjars.bower:bootstrap-sass
CVE-2023-49145 Vulnerability in maven package org.apache.nifi:nifi-jolt-transform-json-ui
CVE-2023-44487 Vulnerability in maven package io.netty:netty-codec-http2
CVE-2022-36909 Vulnerability in maven package org.jenkins-ci.plugins:openshift-deployer