CVE-2022-25850
01.05.2022, 16:15
The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP request is made by a backend server to an untrusted URL submitted by a user. It leads to a leakage of sensitive information from the server.
Vendor | Product | Version |
---|---|---|
proxyscotch_project | proxyscotch | 𝑥 < 1.0.0 |
𝑥
= Vulnerable software versions
References