Description
The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due to flawed DNS rebinding protection.
Remediation
References
https://github.com/ospfranco/link-preview-js/issues/115
https://github.com/ospfranco/link-preview-js/pull/117
https://snyk.io/vuln/SNYK-JS-LINKPREVIEWJS-2933520
Related Vulnerabilities
CVE-2020-7737 Vulnerability in npm package safetydance
CVE-2019-10757 Vulnerability in maven package org.webjars.npm:knex
CVE-2021-23369 Vulnerability in npm package handlebars
CVE-2020-13128 Vulnerability in maven package com.googlecode.gwtupload:gwtupload-project
CVE-2020-13445 Vulnerability in maven package com.liferay:com.liferay.portal.template.velocity