Unsanitized user input in HTTP request (SSRF)
Overview
Description
Remediation Guidelines
const response = axios.get(`https://${req.params.host}`); // riskyconst hosts = new Map([ ["option1", "api1.com"], ["option2", "api2.com"] ]) const host = hosts.get(req.params.host) const response = axios.get(`https://${host}`)
References
Configuration
PreviousUnsanitized user input in HTTP request (SSRF)NextUnsanitized user input in HTTP response (XSS)
Last updated