Vulnerabilities > Request Project > Request > 2.51.0

DATE CVE VULNERABILITY TITLE RISK
2023-03-16 CVE-2023-28155 Server-Side Request Forgery (SSRF) vulnerability in Request Project Request
The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP).
network
low complexity
request-project CWE-918
6.1