-
Notifications
You must be signed in to change notification settings - Fork 10.2k
Mitigations put in place for SSRF in @opennextjs/cloudflare
#23068
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from 1 commit
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change | ||||
|---|---|---|---|---|---|---|
| @@ -0,0 +1,33 @@ | ||||||
| --- | ||||||
| title: SSRF vulnerability in opennextjs-cloudflare via /_next/image endpoint | ||||||
|
||||||
| title: SSRF vulnerability in opennextjs-cloudflare via /_next/image endpoint | |
| title: SSRF vulnerability in @opennextjs/cloudflare proactively mitigated for all Cloudflare customers |
Outdated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
maybe more emphasis on the mitigation than the vuln?
| description: A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package, which has been automatically mitigated for all existing deployments. | |
| description: Mitigations have been put in place for all existing and future deployments of sites with the Cloudflare adapter for Open Next in response to an identified Server-Side Request Forgery (SSRF) vulnerability in the @opennextjs/cloudflare package |
workers-devprod marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
penalosa marked this conversation as resolved.
Outdated
Show resolved
Hide resolved
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Suggest referencing this more directly in first 2-3 sentences
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
same comment here for automatic?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
if the changelog entry should reflect the changes put in place, more than just a notification that a vuln was identified, perhaps: