CVE-2023-28155: SSRF
UNSUPPORTED WHEN ASSIGNED The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Other sources
Node.js Request module is vulnerable to server-side request forgery, caused by a cross-protocol redirect bypass flaw. By sending a specially crafted request, an attacker could exploit this vulnerability to conduct SSRF attack.
— IBM
The request package through 2.88.2 for Node.js and the @cypress/request package prior to 3.0.0 allow a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).
NOTE: The request package is no longer supported by the maintainer.
— GitHub
The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
— Microsoft
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-28155?
CVE-2023-28155 is a vulnerability in the Node.js Request module that allows a bypass of server-side request forgery (SSRF) mitigations through a cross-protocol redirect.
How does CVE-2023-28155 affect Node.js?
CVE-2023-28155 affects Node.js through the Request package up to version 2.88.1 and @cypress/request up to version 2.88.12, allowing SSRF attacks.
What is the severity of CVE-2023-28155?
CVE-2023-28155 has a severity rating of medium with a CVSS score of 6.1.
How can I fix CVE-2023-28155?
To fix CVE-2023-28155, upgrade the Request package to version 2.88.2 or higher, or upgrade @cypress/request to version 3.0.0 or higher.
Is IBM Watson Knowledge Catalog on-prem affected by CVE-2023-28155?
Yes, IBM Watson Knowledge Catalog on-prem versions up to 4.x are affected by CVE-2023-28155.