HIGH
Server-side Request Forgery (SSRF)
Published Oct 20, 2020
7.6
HIGHCVSS 3.1
EPSS 1.60%
Description
This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as an HTML on the page which gives opportunity for XSS or rendered on the server (puppeteer) which also gives opportunity for SSRF and Local File Read.
Affected products
- Vendor n/a Product Osm-Static-Maps Defaultn/a
- Version 0StatusaffectedConstraints<unspecified
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Osm-Static-Maps | n/a |
|
- n/a
No data.
No Red Hat product state for this CVE.
osm-static-maps
npm
Introduced 0 Fixed 3.9.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | osm-static-maps | 0 | 3.9.0 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-1155 Advisory
- https://github.com/advisories/GHSA-pxcf-v868-m492 Advisory
- https://github.com/jperelli/osm-static-maps/blob/master/src/template.html%23L142 x_refsource_MISCBroken Link
- https://github.com/jperelli/osm-static-maps/commit/97355d29e08753d1cfe99b1281dbaa06f4e651b0
- https://github.com/jperelli/osm-static-maps/pull/24 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7749
- https://snyk.io/vuln/SNYK-JS-OSMSTATICMAPS-609637 x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-1155 | Advisory | |
| https://github.com/advisories/GHSA-pxcf-v868-m492 | Advisory | |
| https://github.com/jperelli/osm-static-maps/blob/master/src/template.html%23L142 | x_refsource_MISCBroken Link | |
| https://github.com/jperelli/osm-static-maps/commit/97355d29e08753d1cfe99b1281dbaa06f4e651b0 | ||
| https://github.com/jperelli/osm-static-maps/pull/24 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7749 | ||
| https://snyk.io/vuln/SNYK-JS-OSMSTATICMAPS-609637 | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Oct 20, 2020
Updated Sep 16, 2024
Reserved Jan 21, 2020
Link CVE-2020-7749
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2021-1155 GHSA-PXCF-V868-M492 Assigner snyk
Published Oct 20, 2020
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2021-1155