Description
The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.
Remediation
References
https://hackerone.com/reports/891270
Related Vulnerabilities
CVE-2021-26275 Vulnerability in npm package eslint-fixer
CVE-2020-7238 Vulnerability in maven package io.netty:netty-all
CVE-2022-25940 Vulnerability in npm package lite-server
CVE-2022-45146 Vulnerability in maven package org.bouncycastle:bc-fips
CVE-2022-30506 Vulnerability in maven package net.mingsoft:ms-mcms