@apostrophecms/file npm Package Vulnerability: Early Warning
An early warning has been issued regarding a potential unauthenticated SSRF vulnerability in the @apostrophecms/file npm package when the prettyUrls feature is enabled. This vulnerability could allow an attacker to issue outbound HTTP requests against any host reachable on the private network.
What happened
Reportedly, the @apostrophecms/file npm package is vulnerable to unauthenticated Server-Side Request Forgery (SSRF) via the Host header when the prettyUrls feature is enabled. This vulnerability, tracked under GHSA-34PJ-2622-JVXQ, appears to allow an attacker to pivot the apostrophe process to issue outbound HTTP requests against any host it can reach on the private network.
The vulnerability is under investigation and has been reported to affect versions of @apostrophecms/file up to and including 4.30.0. To assess your exposure, check if your project utilizes the @apostrophecms/file package with the prettyUrls feature enabled.
As a recommended action, it is advised to disable the prettyUrls feature in @apostrophecms/file or upgrade to a version where this issue is fixed once available. For more detailed information, consult the primary sources linked in the summary.
How 0Day mitigates this
@apostrophecms/file is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.