CVE-2023-28155

CVSS V2 None CVSS V3 None
Description
** UNSUPPORTED WHEN ASSIGNED ** The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Overview
  • CVE ID
  • CVE-2023-28155
  • Assigner
  • cve@mitre.org
  • Vulnerability Status
  • Modified
  • Published Version
  • 2023-03-16T15:15:11
  • Last Modified Date
  • 2023-04-13T17:15:17
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:request_project:request:*:*:*:*:*:node.js:*:* 1 OR 2.88.1
References
Reference URL Reference Tags
https://doyensec.com/resources/Doyensec_Advisory_RequestSSRF_Q12023.pdf Exploit Patch Technical Description Third Party Advisory
https://github.com/request/request/issues/3442 Exploit Issue Tracking Patch Technical Description Vendor Advisory
https://github.com/request/request/pull/3444 Patch
https://security.netapp.com/advisory/ntap-20230413-0007/
History
Created Old Value New Value Data Type Notes
2023-04-17 06:35:15 Added to TrackCVE
2023-04-17 06:35:17 Weakness Enumeration new