razorpay is vulnerable to Server-Side Request Forgery (SSRF)
60
Medium Risk
Due to a vulnerability in the request package (CVE-2023-28155), razorpay is vulnerable to server-side request forgery (SSRF). This vulnerability has been fixed in the patch version by replacing the request library with the axios library.
You are affected if you are using a razorpay version which is within vulnerability ranges.
razorpay is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 2.9.3.
Upgrade the razorpay library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant