CVE-2022-24825

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-24825
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-24825.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-24825
Aliases
Related
Published
2022-04-19T20:15:13Z
Modified
2025-07-01T13:41:38.530517Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Smokescreen is a simple HTTP proxy that fogs over naughty URLs. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external attackers leverage the behavior of applications to connect to or scan internal infrastructure. Smokescreen also offers an option to deny access to additional (e.g., external) URLs by way of a deny list. There was an issue in Smokescreen that made it possible to bypass the deny list feature by appending a dot to the end of user-supplied URLs, or by providing input in a different letter case. Recommended to upgrade Smokescreen to version 0.0.3 or later.

References

Affected packages

Git / github.com/stripe/smokescreen

Affected ranges

Type
GIT
Repo
https://github.com/stripe/smokescreen
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.0.2