Server-Side Request Forgeryterriajs-server
terriajs-serverprior to 2.7.4 are vulnerable to Server-Side Request Forgery (SSRF). If an attacker has access to a server whitelisted by the terriajs-server proxy or if the attacker is able to modify the DNS records of a domain whitelisted by the terriajs-server proxy, the attacker can use the terriajs-server proxy to access any HTTP-accessible resources that are accessible to the server, including private resources in the hosting environment.
Upgrade to version 2.7.4 or later.
publishedAdvisory PublishedJan 15th, 2019
reportedReported by Kevin RingJan 15th, 2019