【安全漏洞】NPM IP package vulnerable to Server-Side Request Forgery (SSRF) attacks
see pr: https://github.com/ali-sdk/ali-oss/pull/1292
Hi , I see the PR https://github.com/ali-sdk/ali-oss/pull/1292 got closed... will this be handled ?
This vulnerability still exists... how would this be handled ? urllib latest version is available which is free from vulnerability Thanks
Hi @xiaweiss , any updates on this topic? I see the PR https://github.com/ali-sdk/ali-oss/pull/1292 got closed... will this be handled?
@borisLipmanovich PR #1292 closed, but not merged. holy shit!
urllib version is still 2.41.0 https://github.com/ali-sdk/ali-oss/blob/master/package.json#L156
@xiaweiss, indeed :) Can anyone handle it?
@borisLipmanovich No one is dealing with it, Alibaba doesn't take security seriously, it can be ignored
@xiaweiss, This vulnerability has CVSS 8.6. Maybe you can reopen the PR as it was closed without merging? https://github.com/ali-sdk/ali-oss/pull/1292
@borisLipmanovich please @ repo owner,not me.
I'm just giving feedback, I don't have any access
Version 6.21.0 has been released