Intel

AIKIDO-2024-10175

@cloudflare/next-on-pages is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 11, 2024

60

Medium Risk

This Affects:

JS@cloudflare/next-on-pages
1.4.0 - 1.12.0
Fixed in 1.12.1
Are you affected? Scan for Free

TL;DR

Due to a vulnerability in the image optimization functionality of next, the package is vulnerable to server-side request forgery (SSRF). Protocol-relative URLs are not treated as actual relative URLs.

Who does this affect?

You are affected if you are using a @cloudflare/next-on-pages version which is within vulnerability ranges.

Background info

@cloudflare/next-on-pages is vulnerable to Server-Side Request Forgery (SSRF) in versions 1.4.0 - 1.12.0.

How to fix this

Upgrade the @cloudflare/next-on-pages library to the patch version.