7.5
CVSSv3

CVE-2022-25850

CVSSv4: NA | CVSSv3: 7.5 | CVSSv2: 5 | VMScore: 850 | EPSS: 0.00301 | KEV: Not Included
Published: 01/05/2022 Updated: 21/11/2024

Vulnerability Summary

The package github.com/hoppscotch/proxyscotch prior to 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP request is made by a backend server to an untrusted URL submitted by a user. It leads to a leakage of sensitive information from the server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

* github.com/hoppscotch/proxyscotch

proxyscotch project proxyscotch