CVE-2022-24825

MEDIUM

stripe/smokescreen < 0.0.3 - Server-Side Request Forgery via Deny List Bypass

Title source: llm
STIX 2.1

Description

Smokescreen is a simple HTTP proxy that fogs over naughty URLs. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external attackers leverage the behavior of applications to connect to or scan internal infrastructure. Smokescreen also offers an option to deny access to additional (e.g., external) URLs by way of a deny list. There was an issue in Smokescreen that made it possible to bypass the deny list feature by appending a dot to the end of user-supplied URLs, or by providing input in a different letter case. Recommended to upgrade Smokescreen to version 0.0.3 or later.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://github.com/stripe/smokescreen

Scores

CVSS v3 5.8
EPSS 0.0087
EPSS Percentile 54.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
stripe/smokescreen < 0.0.3
stripe/smokescreen 0 - 0.0.3Go
Published Apr 19, 2022
Tracked Since Feb 18, 2026