FuelSDK-Node-SOAP icon indicating copy to clipboard operation
FuelSDK-Node-SOAP copied to clipboard

Request: Deprecated & Security Issue

Open paulhayeswb opened this issue 1 year ago • 0 comments

The Request package through 2.88.2 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

paulhayeswb avatar Apr 24 '23 16:04 paulhayeswb