Server-side request forgery (SSRF) In thunderbird
Description
A flaw was found in Next.js, a React framework for building web applications. This vulnerability allows a remote attacker to perform Server-Side Request Forgery (SSRF) or Open Redirect attacks. When a rewrites() or redirects() rule constructs an external destination hostname using attacker-controlled input, the application can be coerced into proxying requests to arbitrary hosts, leading to SSRF. Additionally, this misconfiguration can result in Open Redirects, potentially exposing users to phishing.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 15.5.21, 16.2.11 | ||
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
rpm rhel10 | - | - |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5.