Collected research
SSRF Cross Protocol Redirect Bypass
The Node.js request library deletes the custom HTTP agent whenever a redirect switches protocol, which silently discards the anti-SSRF filter attached to that agent. An attacker-controlled open redirect from HTTPS to HTTP therefore defeats ssrf-req-filter and reaches internal services (CVE-2023-28155); axios is exposed the same way when only one of its two agents is overridden.
Record
- Researcher
- Szymon Drosdzol
- Published by
- blog.doyensec.com
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Szymon Drosdzol, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .