Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2023-28155
Disclosure Date: March 16, 2023 (last updated November 08, 2023)
The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
0
Attacker Value
Unknown
CVE-2022-0654
Disclosure Date: February 23, 2022 (last updated February 23, 2025)
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository fgribreau/node-request-retry prior to 7.0.0.
0
Attacker Value
Unknown
CVE-2021-31597
Disclosure Date: April 23, 2021 (last updated February 22, 2025)
The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnauthorized (when the property exists but is undefined) is considered to be false within the https.request function of Node.js. In other words, no certificate is ever rejected.
0
Attacker Value
Unknown
CVE-2020-28502
Disclosure Date: March 05, 2021 (last updated February 22, 2025)
This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run.
0
Attacker Value
Unknown
CVE-2020-13482
Disclosure Date: May 25, 2020 (last updated February 21, 2025)
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
0
Attacker Value
Unknown
CVE-2020-7646
Disclosure Date: May 07, 2020 (last updated February 21, 2025)
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
0
Attacker Value
Unknown
CVE-2019-1010206
Disclosure Date: July 23, 2019 (last updated November 27, 2024)
OSS Http Request (Apache Cordova Plugin) 6 is affected by: Missing SSL certificate validation. The impact is: certificate spoofing. The component is: use this library when https communication. The attack vector is: certificate spoofing.
0
Attacker Value
Unknown
CVE-2017-16073
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
noderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
0
Attacker Value
Unknown
CVE-2017-16026
Disclosure Date: June 04, 2018 (last updated November 26, 2024)
Request is an http client. If a request is made using ```multipart```, and the body type is a ```number```, then the specified number of non-zero memory is passed in the body. This affects Request >=2.2.6 <2.47.0 || >2.51.0 <=2.67.0.
0