Description
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.
Remediation
References
https://hackerone.com/reports/786956
Related Vulnerabilities
CVE-2021-39184 Vulnerability in npm package electron
CVE-2020-29204 Vulnerability in maven package com.xuxueli:xxl-job-admin
CVE-2017-17868 Vulnerability in maven package com.liferay.portal:portal-service
CVE-2022-45401 Vulnerability in maven package org.jenkinsci.plugins:associated-files
CVE-2020-26302 Vulnerability in maven package org.webjars.npm:is_js