cve/2023/CVE-2023-28155.md
2024-05-28 08:49:17 +00:00

958 B

CVE-2023-28155

Description

** UNSUPPORTED WHEN ASSIGNED ** The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

POC

Reference

No PoCs from references.

Github