CVE-2022-25876
Last modified
CVE-2022-25876 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due to flawed DNS rebinding protection.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
The package link-preview-js before 2.1.16 are vulnerable to Server-side Request Forgery (SSRF) which allows attackers to send arbitrary requests to the local network and read the response. This is due to flawed DNS rebinding protection.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Link-Preview-Js Project | Link-Preview-Js | < 2.1.16 |
References
- https://github.com/ospfranco/link-preview-js/issues/115Exploit, Issue Tracking, Third Party Advisory
- https://github.com/ospfranco/link-preview-js/pull/117Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-LINKPREVIEWJS-2933520Exploit, Third Party Advisory
- https://github.com/ospfranco/link-preview-js/issues/115Exploit, Issue Tracking, Third Party Advisory
- https://github.com/ospfranco/link-preview-js/pull/117Patch, Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-LINKPREVIEWJS-2933520Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-25876?
How severe is CVE-2022-25876?
How do I fix CVE-2022-25876?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-2587Out of bounds write in Chrome OS Audio Server in Google Chro…9.8
- CVE-2022-25870Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2022-25871All versions of package querymen are vulnerable to Prototype…7.5
- CVE-2022-25872All versions of package fast-string-search are vulnerable to…5.3
- CVE-2022-25873The package vuetify from 2.0.0-beta.4 and before 2.6.10 are …5.4
- CVE-2022-25875The package svelte before 3.49.0 are vulnerable to Cross-sit…6.1
- CVE-2022-25878The package protobufjs before 6.11.3 are vulnerable to Proto…7.5
- CVE-2022-2588It was discovered that the cls_route filter implementation i…7.8
- CVE-2022-25880Delta Electronics DIAEnergie (All versions prior to 1.8.02.0…9.8
- CVE-2022-25881This affects versions of the package http-cache-semantics be…7.5
- CVE-2022-25882Versions of the package onnx before 1.13.0 are vulnerable to…7.5
- CVE-2022-25883Versions of the package semver before 7.5.2 are vulnerable t…7.5
Are you affected by CVE-2022-25876?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
