GHSA-p8p7-x288-28g6
MODERATECVE-2023-28155The request package through 2.88.2 for Node.js and the @cypress/request package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).
- Affected
- <= 2.88.2
- Fixed in
- not stated
- Weakness
- CWE-918
- Published
- 2023-03-16
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference