ProxyScotch is a simple proxy server created for hoppscotch.io. The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP request is made by a backend server to an untrusted URL submitted by a user. It leads to a leakage of sensitive information from the server.
{ "nvd_published_at": "2022-05-01T16:15:00Z", "github_reviewed_at": "2022-05-04T20:14:02Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-918" ] }