Description
The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.
Remediation
References
https://hackerone.com/reports/891270
Related Vulnerabilities
CVE-2023-4853 Vulnerability in maven package io.quarkus:quarkus-undertow
CVE-2021-23341 Vulnerability in maven package org.webjars:prismjs
CVE-2022-25979 Vulnerability in npm package jsuites
CVE-2020-7706 Vulnerability in npm package connie-lang
CVE-2016-10735 Vulnerability in maven package org.webjars.bower:bootstrap-sass