Vulnerabilities
7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-28155 | The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP t The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NVD description · AI analysis pending | 6.1 | <1% | PoC ×2 |
| — | |
| CVE-2020-28502 | This affects the package xmlhttprequest before 1.7.0; This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run. NVD description · AI analysis pending | 8.1 | 5% | PoC ×4 |
| — | |
| CVE-2020-13482 | EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the librar EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified. NVD description · AI analysis pending | 7.4 | <1% | PoC ×2 |
| — | |
| CVE-2020-7646 | curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input. curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2019-1010206 | OSS Http Request (Apache Cordova Plugin) 6 is affected by: OSS Http Request (Apache Cordova Plugin) 6 is affected by: Missing SSL certificate validation. The impact is: certificate spoofing. The component is: use this library when https communication. The attack vector is: certificate spoofing. NVD description · AI analysis pending | 5.9 | <1% |
| — | ||
| CVE-2017-16073 | noderequest was a malicious module published with the intent to hijack environment variables. noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2017-16026 | Request is an http client. Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 2.51.0 <=2.67.0. NVD description · AI analysis pending | 5.9 | 3% | PoC ×3 |
| — |