High severityNVD Advisory· Published Jan 4, 2022· Updated Aug 2, 2024
Server-Side Request Forgery (SSRF) in transloadit/uppy
CVE-2022-0086
Description
uppy is vulnerable to Server-Side Request Forgery (SSRF)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@uppy/companionnpm | < 3.1.5 | 3.1.5 |
Affected products
2- transloadit/transloadit/uppyv5Range: unspecified
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-x8rq-rc7x-5fg5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-0086ghsaADVISORY
- github.com/transloadit/uppy/commit/fc137e30a2a3102eb191141f280d5de20dacdf8fghsax_refsource_MISCWEB
- github.com/transloadit/uppy/pull/3403ghsaWEB
- github.com/transloadit/uppy/releases/tag/uppy%402.3.3ghsaWEB
- huntr.dev/bounties/c1c03ef6-3f18-4976-a9ad-08c251279122ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.