Junglewise Threat Intelligence

CVE-2020-8135: Uppy Companion server-side request forgery in URL parameter

CVE-2020-8135 · Severity: info · CVSS 0 · Published 2020-09-03

Technologies: @uppy/companion (npm). Vendors: npm.

Executive brief

@uppy/companion is a server component used to handle file uploads in web applications. A vulnerability in versions before 1.9.3 allows attackers to craft malicious requests that cause the server to make unintended HTTP requests to arbitrary URLs, potentially exposing internal services or sensitive data on the network.

Technical details

The vulnerability is a Server-Side Request Forgery (SSRF) in the GET route handler of @uppy/companion. The vulnerable code passes unsanitized user input from req.body.url directly to an HTTP GET request without validation or sanitization. An attacker can inject arbitrary URLs via the url parameter to make the server perform requests to internal IP addresses, private services, or other unintended targets. The attack requires network access to the companion server but no authentication. The vulnerability is fixed in version 1.9.3 and later.

Affected products

  • Uppy companion prior to 1.9.3

Timeline

  • 2020-09-03: disclosed: Advisory published
  • 2020: patched: Fix released in version 1.9.3

References

Related threats