splash@2.3.1 vulnerabilities
A javascript rendered with a HTTP API
-
latest version
3.5
-
first published
10 years ago
-
latest version published
4 years ago
-
licenses detected
- [0,)
Direct Vulnerabilities
Known vulnerabilities in the splash package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
splash is a javascript rendering service with an HTTP API. It’s a lightweight browser with an HTTP API, implemented in Python 3 using Twisted and QT5. It’s fast, lightweight and state-less which makes it easy to distribute. Affected versions of this package are vulnerable to Server-Side Request Forgery (SSRF) via a number of Splash API endpoints (e.g., Furthermore, because Splash processes URLs with the PoC by Claudio Salazar
How to fix Server-Side Request Forgery (SSRF)? There is no fixed version for |
[0,)
|