GHSA-q24h-5rq3-63j9
Dashboard / Vulnerabilities / GHSA-q24h-5rq3-63j9
Summary: Incorrect Authorization in @uppy/companion
Details: @uppy/companion prior to version 3.3.1 is vulnerable to incorrect authorization. A user with URL upload access could enumerate internal companion server networks, send local webservers files to the destination server, and finally download them If each of these files had a guessable and regular name.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-0528, https://github.com/transloadit/uppy/commit/267c34045a1e62c98406d8c31261c604a11e544a, https://github.com/transloadit/uppy, https://huntr.dev/bounties/8b060cc3-2420-468e-8293-b9216620175b
Affected packages
Package
Name: @uppy/companion
Purl: pkg:npm/%40uppy/companion
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -3.3.1
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
