Notice: Breaking change in v4.5.0 (requests to internal IP addresses disallowed)

julian @julian@community.nodebb.org

<p>We are publishing a notice today to bring to attention an unintentional breaking change that could affect some users of NodeBB.</p> <p>v4.5.0 contained an update to <code>src/request.js</code> that calls a DNS resolver to ensure that the destination address is not a reserved IP address (e.g. <code>192.168...</code>, <code>127.0..</code>)</p> <p>This change was introduced in order to close off any potential for <a href="https://owasp.org/www-community/attacks/Server_Side_Request_Forgery" rel="nofollow ugc">Server-Side Request Forgery</a> for any calls made within the NodeBB codebase. [...]</p>

Read more →
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://community.nodebb.org/post/106777 on your instance and quote it. (Note that quoting is not supported in Mastodon.)