PT-2022-13242 · Unknown+1 · @Uppy/Companion+1
Published
2022-03-03
·
Updated
2023-07-10
·
CVE-2022-0528
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
uppy versions prior to 3.3.1
@uppy/companion versions prior to 3.3.1
Description
The issue allows for exposure of sensitive information to an unauthorized actor. It also enables incorrect authorization, where a user with URL upload access could enumerate internal companion server networks, send local web servers files to the destination server, and download them if the files have guessable and regular names.
Recommendations
For uppy versions prior to 3.3.1, update to version 3.3.1 or later.
For @uppy/companion versions prior to 3.3.1, update to version 3.3.1 or later. As a temporary workaround, consider restricting access to the URL upload feature to minimize the risk of exploitation.
Exploit
Fix
Incorrect Authorization
Information Disclosure
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Uppy/Companion
Uppy