ipsambeatae
Version:
Shared dependencies of Compass, the MongoDB extension for VSCode and MongoSH
411 lines (410 loc) • 17.1 kB
JSON
[
{
"vulnerabilities": [
{
"id": "SNYK-JS-REQUEST-3361831",
"title": "Server-side Request Forgery (SSRF)",
"CVSSv3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P",
"credit": ["SzymonDrosdzol"],
"semver": {
"vulnerable": ["*"]
},
"exploit": "Proof of Concept",
"fixedIn": [],
"patches": [],
"insights": {
"triageAdvice": null
},
"language": "js",
"severity": "medium",
"cvssScore": 6.5,
"functions": [],
"malicious": false,
"isDisputed": false,
"moduleName": "request",
"references": [
{
"url": "https://github.com/request/request/commit/d42332182512e56ba68446f49c3e3711e04301a2",
"title": "GitHub Commit"
},
{
"url": "https://github.com/request/request/issues/3442",
"title": "GitHub Issue"
},
{
"url": "https://github.com/request/request/pull/3444",
"title": "GitHub PR"
}
],
"cvssDetails": [
{
"assigner": "NVD",
"severity": "medium",
"cvssV3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"cvssV3BaseScore": 6.1,
"modificationTime": "2023-03-23T01:10:17.579856Z"
}
],
"description": "## Overview\n[request](https://www.npmjs.com/package/request) is a simplified http request client.\n\nAffected versions of this package are vulnerable to Server-side Request Forgery (SSRF) due to insufficient checks in the `lib/redirect.js` file by allowing insecure redirects in the default configuration, via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).\r\n\r\n**NOTE:** This package has been deprecated, so a fix is not expected. See https://github.com/request/request/issues/3142.\n## Remediation\nA fix was pushed into the `master` branch but not yet published.\n## References\n- [GitHub Commit](https://github.com/request/request/commit/d42332182512e56ba68446f49c3e3711e04301a2)\n- [GitHub Issue](https://github.com/request/request/issues/3442)\n- [GitHub PR](https://github.com/request/request/pull/3444)\n",
"epssDetails": {
"percentile": "0.24985",
"probability": "0.00063",
"modelVersion": "v2023.03.01"
},
"identifiers": {
"CVE": ["CVE-2023-28155"],
"CWE": ["CWE-918"]
},
"packageName": "request",
"proprietary": false,
"creationTime": "2023-03-16T13:58:23.124636Z",
"functions_new": [],
"alternativeIds": [],
"disclosureTime": "2023-03-16T13:49:16Z",
"packageManager": "npm",
"publicationTime": "2023-03-17T07:46:44.219769Z",
"modificationTime": "2023-03-23T01:10:17.579856Z",
"socialTrendAlert": false,
"from": [
"mongodb-compass-monorepo@*",
"lerna@4.0.0",
"@lerna/add@4.0.0",
"pacote@11.3.5",
"@npmcli/run-script@1.8.5",
"node-gyp@7.1.2",
"request@2.88.2"
],
"upgradePath": [],
"isUpgradable": false,
"isPatchable": false,
"name": "request",
"version": "2.88.2"
},
{
"id": "SNYK-JS-REQUEST-3361831",
"title": "Server-side Request Forgery (SSRF)",
"CVSSv3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P",
"credit": ["SzymonDrosdzol"],
"semver": {
"vulnerable": ["*"]
},
"exploit": "Proof of Concept",
"fixedIn": [],
"patches": [],
"insights": {
"triageAdvice": null
},
"language": "js",
"severity": "medium",
"cvssScore": 6.5,
"functions": [],
"malicious": false,
"isDisputed": false,
"moduleName": "request",
"references": [
{
"url": "https://github.com/request/request/commit/d42332182512e56ba68446f49c3e3711e04301a2",
"title": "GitHub Commit"
},
{
"url": "https://github.com/request/request/issues/3442",
"title": "GitHub Issue"
},
{
"url": "https://github.com/request/request/pull/3444",
"title": "GitHub PR"
}
],
"cvssDetails": [
{
"assigner": "NVD",
"severity": "medium",
"cvssV3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"cvssV3BaseScore": 6.1,
"modificationTime": "2023-03-23T01:10:17.579856Z"
}
],
"description": "## Overview\n[request](https://www.npmjs.com/package/request) is a simplified http request client.\n\nAffected versions of this package are vulnerable to Server-side Request Forgery (SSRF) due to insufficient checks in the `lib/redirect.js` file by allowing insecure redirects in the default configuration, via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).\r\n\r\n**NOTE:** This package has been deprecated, so a fix is not expected. See https://github.com/request/request/issues/3142.\n## Remediation\nA fix was pushed into the `master` branch but not yet published.\n## References\n- [GitHub Commit](https://github.com/request/request/commit/d42332182512e56ba68446f49c3e3711e04301a2)\n- [GitHub Issue](https://github.com/request/request/issues/3442)\n- [GitHub PR](https://github.com/request/request/pull/3444)\n",
"epssDetails": {
"percentile": "0.24985",
"probability": "0.00063",
"modelVersion": "v2023.03.01"
},
"identifiers": {
"CVE": ["CVE-2023-28155"],
"CWE": ["CWE-918"]
},
"packageName": "request",
"proprietary": false,
"creationTime": "2023-03-16T13:58:23.124636Z",
"functions_new": [],
"alternativeIds": [],
"disclosureTime": "2023-03-16T13:49:16Z",
"packageManager": "npm",
"publicationTime": "2023-03-17T07:46:44.219769Z",
"modificationTime": "2023-03-23T01:10:17.579856Z",
"socialTrendAlert": false,
"from": [
"mongodb-compass-monorepo@*",
"lerna@4.0.0",
"@lerna/add@4.0.0",
"@lerna/bootstrap@4.0.0",
"@lerna/run-lifecycle@4.0.0",
"npm-lifecycle@3.1.5",
"node-gyp@5.1.1",
"request@2.88.2"
],
"upgradePath": [],
"isUpgradable": false,
"isPatchable": false,
"name": "request",
"version": "2.88.2"
},
{
"id": "SNYK-JS-REQUEST-3361831",
"title": "Server-side Request Forgery (SSRF)",
"CVSSv3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P",
"credit": ["SzymonDrosdzol"],
"semver": {
"vulnerable": ["*"]
},
"exploit": "Proof of Concept",
"fixedIn": [],
"patches": [],
"insights": {
"triageAdvice": null
},
"language": "js",
"severity": "medium",
"cvssScore": 6.5,
"functions": [],
"malicious": false,
"isDisputed": false,
"moduleName": "request",
"references": [
{
"url": "https://github.com/request/request/commit/d42332182512e56ba68446f49c3e3711e04301a2",
"title": "GitHub Commit"
},
{
"url": "https://github.com/request/request/issues/3442",
"title": "GitHub Issue"
},
{
"url": "https://github.com/request/request/pull/3444",
"title": "GitHub PR"
}
],
"cvssDetails": [
{
"assigner": "NVD",
"severity": "medium",
"cvssV3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"cvssV3BaseScore": 6.1,
"modificationTime": "2023-03-23T01:10:17.579856Z"
}
],
"description": "## Overview\n[request](https://www.npmjs.com/package/request) is a simplified http request client.\n\nAffected versions of this package are vulnerable to Server-side Request Forgery (SSRF) due to insufficient checks in the `lib/redirect.js` file by allowing insecure redirects in the default configuration, via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).\r\n\r\n**NOTE:** This package has been deprecated, so a fix is not expected. See https://github.com/request/request/issues/3142.\n## Remediation\nA fix was pushed into the `master` branch but not yet published.\n## References\n- [GitHub Commit](https://github.com/request/request/commit/d42332182512e56ba68446f49c3e3711e04301a2)\n- [GitHub Issue](https://github.com/request/request/issues/3442)\n- [GitHub PR](https://github.com/request/request/pull/3444)\n",
"epssDetails": {
"percentile": "0.24985",
"probability": "0.00063",
"modelVersion": "v2023.03.01"
},
"identifiers": {
"CVE": ["CVE-2023-28155"],
"CWE": ["CWE-918"]
},
"packageName": "request",
"proprietary": false,
"creationTime": "2023-03-16T13:58:23.124636Z",
"functions_new": [],
"alternativeIds": [],
"disclosureTime": "2023-03-16T13:49:16Z",
"packageManager": "npm",
"publicationTime": "2023-03-17T07:46:44.219769Z",
"modificationTime": "2023-03-23T01:10:17.579856Z",
"socialTrendAlert": false,
"from": [
"mongodb-compass-monorepo@*",
"@mongodb-js/bump-monorepo-packages@0.2.1",
"lerna@4.0.0",
"@lerna/add@4.0.0",
"pacote@11.3.5",
"@npmcli/run-script@1.8.5",
"node-gyp@7.1.2",
"request@2.88.2"
],
"upgradePath": [],
"isUpgradable": false,
"isPatchable": false,
"name": "request",
"version": "2.88.2"
},
{
"id": "SNYK-JS-REQUEST-3361831",
"title": "Server-side Request Forgery (SSRF)",
"CVSSv3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P",
"credit": ["SzymonDrosdzol"],
"semver": {
"vulnerable": ["*"]
},
"exploit": "Proof of Concept",
"fixedIn": [],
"patches": [],
"insights": {
"triageAdvice": null
},
"language": "js",
"severity": "medium",
"cvssScore": 6.5,
"functions": [],
"malicious": false,
"isDisputed": false,
"moduleName": "request",
"references": [
{
"url": "https://github.com/request/request/commit/d42332182512e56ba68446f49c3e3711e04301a2",
"title": "GitHub Commit"
},
{
"url": "https://github.com/request/request/issues/3442",
"title": "GitHub Issue"
},
{
"url": "https://github.com/request/request/pull/3444",
"title": "GitHub PR"
}
],
"cvssDetails": [
{
"assigner": "NVD",
"severity": "medium",
"cvssV3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"cvssV3BaseScore": 6.1,
"modificationTime": "2023-03-23T01:10:17.579856Z"
}
],
"description": "## Overview\n[request](https://www.npmjs.com/package/request) is a simplified http request client.\n\nAffected versions of this package are vulnerable to Server-side Request Forgery (SSRF) due to insufficient checks in the `lib/redirect.js` file by allowing insecure redirects in the default configuration, via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).\r\n\r\n**NOTE:** This package has been deprecated, so a fix is not expected. See https://github.com/request/request/issues/3142.\n## Remediation\nA fix was pushed into the `master` branch but not yet published.\n## References\n- [GitHub Commit](https://github.com/request/request/commit/d42332182512e56ba68446f49c3e3711e04301a2)\n- [GitHub Issue](https://github.com/request/request/issues/3442)\n- [GitHub PR](https://github.com/request/request/pull/3444)\n",
"epssDetails": {
"percentile": "0.24985",
"probability": "0.00063",
"modelVersion": "v2023.03.01"
},
"identifiers": {
"CVE": ["CVE-2023-28155"],
"CWE": ["CWE-918"]
},
"packageName": "request",
"proprietary": false,
"creationTime": "2023-03-16T13:58:23.124636Z",
"functions_new": [],
"alternativeIds": [],
"disclosureTime": "2023-03-16T13:49:16Z",
"packageManager": "npm",
"publicationTime": "2023-03-17T07:46:44.219769Z",
"modificationTime": "2023-03-23T01:10:17.579856Z",
"socialTrendAlert": false,
"from": [
"mongodb-compass-monorepo@*",
"@mongodb-js/bump-monorepo-packages@0.2.1",
"lerna@4.0.0",
"@lerna/add@4.0.0",
"@lerna/bootstrap@4.0.0",
"@lerna/run-lifecycle@4.0.0",
"npm-lifecycle@3.1.5",
"node-gyp@5.1.1",
"request@2.88.2"
],
"upgradePath": [],
"isUpgradable": false,
"isPatchable": false,
"name": "request",
"version": "2.88.2"
},
{
"id": "SNYK-JS-REQUEST-3361831",
"title": "Server-side Request Forgery (SSRF)",
"CVSSv3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:P",
"credit": ["SzymonDrosdzol"],
"semver": {
"vulnerable": ["*"]
},
"exploit": "Proof of Concept",
"fixedIn": [],
"patches": [],
"insights": {
"triageAdvice": null
},
"language": "js",
"severity": "medium",
"cvssScore": 6.5,
"functions": [],
"malicious": false,
"isDisputed": false,
"moduleName": "request",
"references": [
{
"url": "https://github.com/request/request/commit/d42332182512e56ba68446f49c3e3711e04301a2",
"title": "GitHub Commit"
},
{
"url": "https://github.com/request/request/issues/3442",
"title": "GitHub Issue"
},
{
"url": "https://github.com/request/request/pull/3444",
"title": "GitHub PR"
}
],
"cvssDetails": [
{
"assigner": "NVD",
"severity": "medium",
"cvssV3Vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"cvssV3BaseScore": 6.1,
"modificationTime": "2023-03-23T01:10:17.579856Z"
}
],
"description": "## Overview\n[request](https://www.npmjs.com/package/request) is a simplified http request client.\n\nAffected versions of this package are vulnerable to Server-side Request Forgery (SSRF) due to insufficient checks in the `lib/redirect.js` file by allowing insecure redirects in the default configuration, via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).\r\n\r\n**NOTE:** This package has been deprecated, so a fix is not expected. See https://github.com/request/request/issues/3142.\n## Remediation\nA fix was pushed into the `master` branch but not yet published.\n## References\n- [GitHub Commit](https://github.com/request/request/commit/d42332182512e56ba68446f49c3e3711e04301a2)\n- [GitHub Issue](https://github.com/request/request/issues/3442)\n- [GitHub PR](https://github.com/request/request/pull/3444)\n",
"epssDetails": {
"percentile": "0.24985",
"probability": "0.00063",
"modelVersion": "v2023.03.01"
},
"identifiers": {
"CVE": ["CVE-2023-28155"],
"CWE": ["CWE-918"]
},
"packageName": "request",
"proprietary": false,
"creationTime": "2023-03-16T13:58:23.124636Z",
"functions_new": [],
"alternativeIds": [],
"disclosureTime": "2023-03-16T13:49:16Z",
"packageManager": "npm",
"publicationTime": "2023-03-17T07:46:44.219769Z",
"modificationTime": "2023-03-23T01:10:17.579856Z",
"socialTrendAlert": false,
"from": [
"mongodb-compass-monorepo@*",
"@webpack-cli/serve@0.2.0",
"@webpack-cli/utils@0.2.3",
"jest@24.9.0",
"jest-cli@24.9.0",
"@jest/core@24.9.0",
"@jest/reporters@24.9.0",
"jest-runtime@24.9.0",
"jest-config@24.9.0",
"jest-environment-jsdom@24.9.0",
"jsdom@11.12.0",
"request@2.88.2"
],
"upgradePath": [],
"isUpgradable": false,
"isPatchable": false,
"name": "request",
"version": "2.88.2"
}
]
}
]