drupal/core is vulnerable to Server-side Request Forgery (SSRF)
49
Medium Risk
The Media module's oEmbed support — which implements the spec's two discovery mechanisms, providers.json and URL discovery — contains a flaw in the URL discovery logic that can be abused to trick Drupal into issuing server-side requests to arbitrary attacker-controlled URLs, resulting in a Server-Side Request Forgery (SSRF) vulnerability.
You are affected if you are using a version that falls within the vulnerable range.
drupal/core is vulnerable to Server-side Request Forgery (SSRF) in versions 0.0.0 - 10.5.11, 10.6.0 - 10.6.10, 11.0.0 - 11.2.13 and 11.3.0 - 11.3.11.
Upgrade the drupal/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant