-
-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Got allows a redirect to a UNIX socket #105
Labels
Auto Create Issues
Label for Auto Created Issues
do-not-autoclose
Make bot can't close an Issues or PRs
Moderate
This label for Security Severity only
Security
Label for Security Issues
Milestone
Comments
Stale issue message |
P |
Isu ini sudah tidak ada perkembangan |
Isu ini sudah tidak ada perkembangan |
Isu ini sudah tidak ada perkembangan |
Isu ini sudah tidak ada perkembangan |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Auto Create Issues
Label for Auto Created Issues
do-not-autoclose
Make bot can't close an Issues or PRs
Moderate
This label for Security Severity only
Security
Label for Security Issues
Description
The got package before 11.8.5 and 12.1.0 for Node.js allows a redirect to a UNIX socket.
Severity Check
Severity Number
5.8
CVSS base metrics
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weaknesses
No CWEs
CVE ID
CVE-2022-33987
GHSA ID
GHSA-pfrx-2q88-qq97
Information
Package
got (npm)
Affected versions
12.1.0
11.8.5
References
https://nvd.nist.gov/vuln/detail/CVE-2022-33987
Disable redirects to UNIX sockets sindresorhus/got#2047
sindresorhus/[email protected]
sindresorhus/got@861ccd9
https://github.com/sindresorhus/got/releases/tag/v11.8.5
https://github.com/sindresorhus/got/releases/tag/v12.1.0
The text was updated successfully, but these errors were encountered: