Executive brief
The Request library is a widely-used Node.js package for making HTTP requests in applications. An attacker can bypass the library's built-in protections against Server-Side Request Forgery (SSRF) attacks by setting up a malicious server that redirects requests between protocols (HTTP to HTTPS or vice versa). This could allow an attacker to access internal systems or services that the application should not be able to reach.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the Request library (through version 2.88.2) and @cypress/request (prior to 3.0.0) due to improper validation of SSRF mitigations during cross-protocol redirects. The vulnerable code in the redirect handling logic fails to properly validate requests when a server responds with a redirect from HTTP to HTTPS or vice versa. An attacker controlling a malicious server can craft a redirect response that bypasses the existing SSRF protections, allowing the application to make requests to internal or restricted resources. The attack requires network-level access to intercept or control redirect responses but does not require authentication or user interaction. Patches are available: Request is no longer maintained; @cypress/request has been fixed in version 3.0.0.
Affected products
- Request request through 2.88.2
- Cypress @cypress/request prior to 3.0.0
Timeline
- 2023-03-16: disclosed: Advisory published
- 2023-03-16: patched: @cypress/request version 3.0.0 released with fix