PT-2022-13242 · Unknown+1 · @Uppy/Companion+1

Published

2022-03-03

·

Updated

2023-07-10

·

CVE-2022-0528

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions uppy versions prior to 3.3.1 @uppy/companion versions prior to 3.3.1
Description The issue allows for exposure of sensitive information to an unauthorized actor. It also enables incorrect authorization, where a user with URL upload access could enumerate internal companion server networks, send local web servers files to the destination server, and download them if the files have guessable and regular names.
Recommendations For uppy versions prior to 3.3.1, update to version 3.3.1 or later. For @uppy/companion versions prior to 3.3.1, update to version 3.3.1 or later. As a temporary workaround, consider restricting access to the URL upload feature to minimize the risk of exploitation.

Exploit

Fix

Incorrect Authorization

Information Disclosure

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0528
GHSA-Q24H-5RQ3-63J9

Affected Products

@Uppy/Companion
Uppy