Description
The uppy npm package < 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.
Remediation
References
https://hackerone.com/reports/786956
Related Vulnerabilities
CVE-2020-28502 Vulnerability in maven package org.webjars.npm:xmlhttprequest
CVE-2020-26301 Vulnerability in npm package ssh2
CVE-2022-29002 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2021-25978 Vulnerability in npm package apostrophe
CVE-2022-23106 Vulnerability in maven package io.jenkins:configuration-as-code