prebid-server Package Vulnerability: Request Forgery Threat
An early warning has been issued regarding a request forgery vulnerability in the prebid-server package, which may allow for host environment data extraction. Affected versions include v2, v3, and v4.
What happened
The prebid-server package is under investigation for a vulnerability that could enable request forgery, potentially leading to the extraction of host environment data. This issue arises from certain bidder adapters that accept user-supplied parameters interpolated into outbound request URLs. Without adequate input validation, a malicious actor might exploit this to direct the server to send HTTP requests to unintended destinations, risking exposure of internal network services or sensitive server endpoints.
Professional software engineers using prebid-server versions v2, v3, or v4 are advised to assess their exposure. The recommended actions include upgrading to prebid-server v4.4.0 or disabling the affected bidder adapters if an update is not feasible. For the most accurate and detailed information, consulting the primary sources is advised.
How 0Day mitigates this
prebid-server is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.