Description
The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.
Remediation
References
https://hackerone.com/reports/891270
Related Vulnerabilities
CVE-2022-22965 Vulnerability in maven package org.springframework:spring-webflux
CVE-2022-4244 Vulnerability in maven package org.codehaus.plexus:plexus-utils
CVE-2021-29479 Vulnerability in maven package io.ratpack:ratpack-core
CVE-2022-31051 Vulnerability in npm package semantic-release
CVE-2022-23621 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore