7.5
CVSSv3

CVE-2020-8205

Published: 20/07/2020 Updated: 23/07/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an malicious user to scan local or external networks or otherwise interact with internal systems.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

transloadit uppy

transloadit uppy 2.0.0