CVE-2023-28155: SSRF
UNSUPPORTED WHEN ASSIGNED The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Other sources
The request package through 2.88.2 for Node.js and the @cypress/request package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).
NOTE: The request package is no longer supported by the maintainer.
— GitHub
The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@cypress/requestto a version that resolves this vulnerability.Fixed in 3.0.0 - Upgrade
Upgrade
request (Node.js)to a version that resolves this vulnerability.Fixed in 2.88.2 - Upgrade
Upgrade
@cypress/request (Node.js)to a version that resolves this vulnerability.Fixed in 3.0.0
Event History
Frequently Asked Questions
What is CVE-2023-28155?
CVE-2023-28155 is a vulnerability in the Node.js Request module that allows a bypass of server-side request forgery (SSRF) mitigations through a cross-protocol redirect.
How does CVE-2023-28155 affect Node.js?
CVE-2023-28155 affects Node.js through the Request package up to version 2.88.1 and @cypress/request up to version 2.88.12, allowing SSRF attacks.
What is the severity of CVE-2023-28155?
CVE-2023-28155 has a severity rating of medium with a CVSS score of 6.1.
How can I fix CVE-2023-28155?
To fix CVE-2023-28155, upgrade the Request package to version 2.88.2 or higher, or upgrade @cypress/request to version 3.0.0 or higher.
Is IBM Watson Knowledge Catalog on-prem affected by CVE-2023-28155?
Yes, IBM Watson Knowledge Catalog on-prem versions up to 4.x are affected by CVE-2023-28155.