@cypress/request
Releases24
Frequency3 months 1 week
Last Release
Cypress's fork of a simplified HTTP request client.
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| <= 2.88.1, <= 2.88.2, < 3.0.0 | 6.1 MEDIUM | — | ||
The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | ||||