CVE-2023-28155
CVSS V2 None
CVSS V3 None
Description
** UNSUPPORTED WHEN ASSIGNED ** The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Overview
- CVE ID
- CVE-2023-28155
- Assigner
- cve@mitre.org
- Vulnerability Status
- Modified
- Published Version
- 2023-03-16T15:15:11
- Last Modified Date
- 2023-04-13T17:15:17
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:request_project:request:*:*:*:*:*:node.js:*:* | 1 | OR | 2.88.1 |
References
Reference URL | Reference Tags |
---|---|
https://doyensec.com/resources/Doyensec_Advisory_RequestSSRF_Q12023.pdf | Exploit Patch Technical Description Third Party Advisory |
https://github.com/request/request/issues/3442 | Exploit Issue Tracking Patch Technical Description Vendor Advisory |
https://github.com/request/request/pull/3444 | Patch |
https://security.netapp.com/advisory/ntap-20230413-0007/ |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-28155 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28155 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 06:35:15 | Added to TrackCVE | |||
2023-04-17 06:35:17 | Weakness Enumeration | new |