mockttp is vulnerable to Binding to an Unrestricted IP Address
75
High Risk
The optional remote admin server binds to all network interfaces (0.0.0.0) by default when it is started without an explicit host, or with only a port. Any party with network access to the admin port can then configure and start mock servers with custom rules without authentication. This can be abused to read process-readable files from the host machine and retrieve them through a dynamically created mock server. The fix changes the default bind host to 127.0.0.1 so the admin API only accepts local connections unless explicitly configured otherwise.
You are affected if you are using a version that falls within the vulnerable range and you enable the remote admin server with default or port-only settings so it binds to all network interfaces and is reachable by untrusted parties.
mockttp is vulnerable to Binding to an Unrestricted IP Address in versions 0.0.1 - 3.17.1 and 4.0.0 - 4.5.0.
Upgrade the mockttp library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant