{"id":"CVE-2020-8135","details":"The uppy npm package \u003c 1.9.3 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external network or otherwise interact with internal systems.","aliases":["GHSA-mm7r-265w-jv6f"],"modified":"2026-04-10T04:28:20.258268Z","published":"2020-03-20T19:15:12.877Z","references":[{"type":"FIX","url":"https://hackerone.com/reports/786956"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/transloadit/uppy","events":[{"introduced":"0"},{"fixed":"b20bc7e1f1a3e4132dde0c311fff1ff18080414c"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"1.9.3"}]}}],"versions":["@uppy/aws-s3-multipart@0.26.0","@uppy/aws-s3-multipart@0.27.1","@uppy/aws-s3-multipart@0.27.2","@uppy/aws-s3-multipart@0.27.3","@uppy/aws-s3-multipart@0.27.4","@uppy/aws-s3-multipart@0.28.0","@uppy/aws-s3-multipart@0.29.0","@uppy/aws-s3-multipart@0.30.1","@uppy/aws-s3-multipart@0.30.3","@uppy/aws-s3-multipart@0.30.4","@uppy/aws-s3-multipart@0.30.5","@uppy/aws-s3-multipart@1.0.1","@uppy/aws-s3-multipart@1.0.2","@uppy/aws-s3-multipart@1.1.0","@uppy/aws-s3-multipart@1.2.0","@uppy/aws-s3-multipart@1.3.0","@uppy/aws-s3-multipart@1.3.1","@uppy/aws-s3-multipart@1.3.2","@uppy/aws-s3-multipart@1.3.3","@uppy/aws-s3-multipart@1.3.4","@uppy/aws-s3-multipart@1.3.5","@uppy/aws-s3-multipart@1.4.0","@uppy/aws-s3-multipart@1.5.2","@uppy/aws-s3@0.26.0","@uppy/aws-s3@0.27.1","@uppy/aws-s3@0.27.2","@uppy/aws-s3@0.27.3","@uppy/aws-s3@0.27.4","@uppy/aws-s3@0.28.0","@uppy/aws-s3@0.29.0","@uppy/aws-s3@0.30.1","@uppy/aws-s3@0.30.3","@uppy/aws-s3@0.30.4","@uppy/aws-s3@0.30.5","@uppy/aws-s3@1.0.1","@uppy/aws-s3@1.0.2","@uppy/aws-s3@1.1.0","@uppy/aws-s3@1.2.0","@uppy/aws-s3@1.3.0","@uppy/aws-s3@1.3.1","@uppy/aws-s3@1.3.2","@uppy/aws-s3@1.3.3","@uppy/aws-s3@1.4.0","@uppy/aws-s3@1.4.1","@uppy/aws-s3@1.5.2","@uppy/companion-client@0.27.1","@uppy/companion-client@0.27.2","@uppy/companion-client@0.28.1","@uppy/companion-client@0.28.3","@uppy/companion-client@0.28.4","@uppy/companion-client@0.28.5","@uppy/companion-client@1.0.1","@uppy/companion-client@1.1.0","@uppy/companion-client@1.2.0","@uppy/companion-client@1.3.0","@uppy/companion-client@1.4.0","@uppy/companion-client@1.4.1","@uppy/companion-client@1.4.2","@uppy/companion@0.14.1","@uppy/companion@0.14.2","@uppy/companion@0.14.3","@uppy/companion@0.14.4","@uppy/companion@0.15.0","@uppy/companion@0.16.0","@uppy/companion@0.17.1","@uppy/companion@0.17.3","@uppy/companion@0.17.4","@uppy/companion@0.17.5","@uppy/companion@1.0.1","@uppy/companion@1.0.2","@uppy/companion@1.1.0","@uppy/companion@1.2.0","@uppy/companion@1.3.0","@uppy/companion@1.4.0","@uppy/companion@1.5.0","@uppy/companion@1.6.0","@uppy/companion@1.7.0","@uppy/companion@1.8.0","@uppy/companion@1.9.2","@uppy/core@0.26.0","@uppy/core@0.27.1","@uppy/core@0.27.2","@uppy/core@0.27.3","@uppy/core@0.28.0","@uppy/core@0.29.0","@uppy/core@0.30.1","@uppy/core@0.30.3","@uppy/core@0.30.4","@uppy/core@0.30.5","@uppy/core@1.0.1","@uppy/core@1.0.2","@uppy/core@1.1.0","@uppy/core@1.2.0","@uppy/core@1.4.0","@uppy/core@1.5.0","@uppy/core@1.5.1","@uppy/core@1.6.0","@uppy/core@1.7.0","@uppy/core@1.7.1","@uppy/core@1.8.2","@uppy/dashboard@0.26.0","@uppy/dashboard@0.27.1","@uppy/dashboard@0.27.2","@uppy/dashboard@0.27.3","@uppy/dashboard@0.27.4","@uppy/dashboard@0.27.5","@uppy/dashboard@0.28.0","@uppy/dashboard@0.29.0","@uppy/dashboard@0.30.1","@uppy/dashboard@0.30.3","@uppy/dashboard@0.30.4","@uppy/dashboard@0.30.5","@uppy/dashboard@1.0.1","@uppy/dashboard@1.0.2","@uppy/dashboard@1.1.0","@uppy/dashboard@1.2.0","@uppy/dashboard@1.3.0","@uppy/dashboard@1.4.0","@uppy/dashboard@1.4.1","@uppy/dashboard@1.5.0","@uppy/dashboard@1.5.1","@uppy/dashboard@1.5.2","@uppy/dashboard@1.6.2","@uppy/drag-drop@0.26.0","@uppy/drag-drop@0.27.1","@uppy/drag-drop@0.27.2","@uppy/drag-drop@0.27.3","@uppy/drag-drop@0.27.4","@uppy/drag-drop@0.28.0","@uppy/drag-drop@0.29.0","@uppy/drag-drop@0.30.1","@uppy/drag-drop@0.30.3","@uppy/drag-drop@0.30.4","@uppy/drag-drop@0.30.5","@uppy/drag-drop@1.0.1","@uppy/drag-drop@1.0.2","@uppy/drag-drop@1.1.0","@uppy/drag-drop@1.2.0","@uppy/drag-drop@1.3.0","@uppy/drag-drop@1.3.1","@uppy/drag-drop@1.4.0","@uppy/drag-drop@1.4.1","@uppy/drag-drop@1.4.2","@uppy/drag-drop@1.4.5","@uppy/dropbox@0.26.0","@uppy/dropbox@0.27.1","@uppy/dropbox@0.27.2","@uppy/dropbox@0.27.3","@uppy/dropbox@0.27.4","@uppy/dropbox@0.28.0","@uppy/dropbox@0.29.0","@uppy/dropbox@0.30.1","@uppy/dropbox@0.30.3","@uppy/dropbox@0.30.4","@uppy/dropbox@0.30.5","@uppy/dropbox@1.0.1","@uppy/dropbox@1.0.2","@uppy/dropbox@1.1.0","@uppy/dropbox@1.2.0","@uppy/dropbox@1.3.0","@uppy/dropbox@1.3.1","@uppy/dropbox@1.3.2","@uppy/dropbox@1.3.3","@uppy/dropbox@1.3.4","@uppy/dropbox@1.3.5","@uppy/dropbox@1.3.8","@uppy/facebook@0.1.0","@uppy/facebook@0.1.1","@uppy/facebook@0.2.0","@uppy/facebook@0.2.1","@uppy/facebook@0.2.2","@uppy/facebook@0.2.5","@uppy/file-input@0.26.0","@uppy/file-input@0.27.1","@uppy/file-input@0.27.2","@uppy/file-input@0.27.3","@uppy/file-input@0.27.4","@uppy/file-input@0.28.0","@uppy/file-input@0.29.0","@uppy/file-input@0.30.1","@uppy/file-input@0.30.3","@uppy/file-input@0.30.4","@uppy/file-input@0.30.5","@uppy/file-input@1.0.1","@uppy/file-input@1.0.2","@uppy/file-input@1.1.0","@uppy/file-input@1.2.0","@uppy/file-input@1.3.0","@uppy/file-input@1.3.1","@uppy/file-input@1.4.0","@uppy/file-input@1.4.1","@uppy/file-input@1.4.2","@uppy/file-input@1.4.5","@uppy/form@0.26.0","@uppy/form@0.27.1","@uppy/form@0.27.2","@uppy/form@0.27.3","@uppy/form@0.27.4","@uppy/form@0.28.0","@uppy/form@0.29.0","@uppy/form@0.30.1","@uppy/form@0.30.3","@uppy/form@0.30.4","@uppy/form@0.30.5","@uppy/form@1.0.1","@uppy/form@1.0.2","@uppy/form@1.1.0","@uppy/form@1.2.0","@uppy/form@1.3.0","@uppy/form@1.3.1","@uppy/form@1.3.2","@uppy/form@1.3.3","@uppy/form@1.3.4","@uppy/form@1.3.5","@uppy/form@1.3.8","@uppy/golden-retriever@0.26.0","@uppy/golden-retriever@0.27.1","@uppy/golden-retriever@0.27.2","@uppy/golden-retriever@0.27.3","@uppy/golden-retriever@0.27.4","@uppy/golden-retriever@0.28.0","@uppy/golden-retriever@0.29.0","@uppy/golden-retriever@0.30.1","@uppy/golden-retriever@0.30.3","@uppy/golden-retriever@0.30.4","@uppy/golden-retriever@0.30.5","@uppy/golden-retriever@1.0.1","@uppy/golden-retriever@1.0.2","@uppy/golden-retriever@1.1.0","@uppy/golden-retriever@1.2.0","@uppy/golden-retriever@1.3.0","@uppy/golden-retriever@1.3.1","@uppy/golden-retriever@1.3.2","@uppy/golden-retriever@1.3.3","@uppy/golden-retriever@1.3.4","@uppy/golden-retriever@1.3.7","@uppy/google-drive@0.26.0","@uppy/google-drive@0.27.1","@uppy/google-drive@0.27.2","@uppy/google-drive@0.27.3","@uppy/google-drive@0.27.4","@uppy/google-drive@0.27.5","@uppy/google-drive@0.28.0","@uppy/google-drive@0.29.0","@uppy/google-drive@0.30.1","@uppy/google-drive@0.30.3","@uppy/google-drive@0.30.4","@uppy/google-drive@0.30.5","@uppy/google-drive@1.0.1","@uppy/google-drive@1.0.2","@uppy/google-drive@1.1.0","@uppy/google-drive@1.2.0","@uppy/google-drive@1.3.0","@uppy/google-drive@1.3.1","@uppy/google-drive@1.3.2","@uppy/google-drive@1.3.3","@uppy/google-drive@1.3.4","@uppy/google-drive@1.3.5","@uppy/google-drive@1.4.2","@uppy/informer@0.26.0","@uppy/informer@0.27.1","@uppy/informer@0.27.2","@uppy/informer@0.27.3","@uppy/informer@0.27.4","@uppy/informer@0.28.0","@uppy/informer@0.29.0","@uppy/informer@0.30.1","@uppy/informer@0.30.3","@uppy/informer@0.30.4","@uppy/informer@0.30.5","@uppy/informer@1.0.1","@uppy/informer@1.0.2","@uppy/informer@1.1.0","@uppy/informer@1.2.0","@uppy/informer@1.3.0","@uppy/informer@1.3.1","@uppy/informer@1.3.2","@uppy/informer@1.3.3","@uppy/informer@1.3.4","@uppy/informer@1.4.2","@uppy/instagram@0.26.0","@uppy/instagram@0.27.1","@uppy/instagram@0.27.2","@uppy/instagram@0.27.3","@uppy/instagram@0.27.4","@uppy/instagram@0.27.5","@uppy/instagram@0.28.0","@uppy/instagram@0.29.0","@uppy/instagram@0.30.1","@uppy/instagram@0.30.3","@uppy/instagram@0.30.4","@uppy/instagram@0.30.5","@uppy/instagram@1.0.1","@uppy/instagram@1.0.2","@uppy/instagram@1.1.0","@uppy/instagram@1.2.0","@uppy/instagram@1.3.0","@uppy/instagram@1.3.1","@uppy/instagram@1.3.2","@uppy/instagram@1.3.3","@uppy/instagram@1.3.4","@uppy/instagram@1.3.5","@uppy/instagram@1.3.8","@uppy/locales@0.30.5","@uppy/locales@1.1.0","@uppy/locales@1.10.0","@uppy/locales@1.11.0","@uppy/locales@1.11.3","@uppy/locales@1.2.0","@uppy/locales@1.3.0","@uppy/locales@1.4.0","@uppy/locales@1.5.0","@uppy/locales@1.6.0","@uppy/locales@1.7.0","@uppy/locales@1.8.0","@uppy/locales@1.9.0","@uppy/onedrive@0.1.0","@uppy/onedrive@0.1.1","@uppy/onedrive@0.1.2","@uppy/onedrive@0.1.3","@uppy/onedrive@0.1.4","@uppy/onedrive@1.0.2","@uppy/progress-bar@0.26.0","@uppy/progress-bar@0.27.1","@uppy/progress-bar@0.27.2","@uppy/progress-bar@0.27.3","@uppy/progress-bar@0.27.4","@uppy/progress-bar@0.28.0","@uppy/progress-bar@0.29.0","@uppy/progress-bar@0.30.1","@uppy/progress-bar@0.30.3","@uppy/progress-bar@0.30.4","@uppy/progress-bar@0.30.5","@uppy/progress-bar@1.0.1","@uppy/progress-bar@1.0.2","@uppy/progress-bar@1.1.0","@uppy/progress-bar@1.2.0","@uppy/progress-bar@1.3.0","@uppy/progress-bar@1.3.1","@uppy/progress-bar@1.3.2","@uppy/progress-bar@1.3.3","@uppy/progress-bar@1.3.4","@uppy/progress-bar@1.3.7","@uppy/provider-views@0.26.0","@uppy/provider-views@0.27.1","@uppy/provider-views@0.27.2","@uppy/provider-views@0.27.3","@uppy/provider-views@0.27.4","@uppy/provider-views@0.28.0","@uppy/provider-views@0.29.0","@uppy/provider-views@0.30.1","@uppy/provider-views@0.30.3","@uppy/provider-views@0.30.4","@uppy/provider-views@0.30.5","@uppy/provider-views@1.0.1","@uppy/provider-views@1.0.2","@uppy/provider-views@1.1.0","@uppy/provider-views@1.2.0","@uppy/provider-views@1.3.0","@uppy/provider-views@1.4.0","@uppy/provider-views@1.5.0","@uppy/provider-views@1.5.1","@uppy/provider-views@1.5.2","@uppy/provider-views@1.5.5","@uppy/react-native@0.0.3","@uppy/react-native@0.1.1","@uppy/react-native@0.1.2","@uppy/react-native@0.1.3","@uppy/react@0.26.0","@uppy/react@0.27.1","@uppy/react@0.27.2","@uppy/react@0.27.3","@uppy/react@0.27.4","@uppy/react@0.27.5","@uppy/react@0.28.0","@uppy/react@0.29.0","@uppy/react@0.30.1","@uppy/react@0.30.3","@uppy/react@0.30.4","@uppy/react@0.30.5","@uppy/react@1.0.1","@uppy/react@1.0.2","@uppy/react@1.1.0","@uppy/react@1.2.0","@uppy/react@1.3.0","@uppy/react@1.3.1","@uppy/react@1.3.2","@uppy/react@1.4.0","@uppy/react@1.4.1","@uppy/react@1.4.2","@uppy/react@1.4.5","@uppy/redux-dev-tools@0.26.0","@uppy/redux-dev-tools@0.27.1","@uppy/redux-dev-tools@0.27.2","@uppy/redux-dev-tools@0.27.3","@uppy/redux-dev-tools@0.27.4","@uppy/redux-dev-tools@0.28.0","@uppy/redux-dev-tools@0.29.0","@uppy/redux-dev-tools@0.30.1","@uppy/redux-dev-tools@0.30.3","@uppy/redux-dev-tools@0.30.4","@uppy/redux-dev-tools@0.30.5","@uppy/redux-dev-tools@1.0.1","@uppy/redux-dev-tools@1.0.2","@uppy/redux-dev-tools@1.1.0","@uppy/redux-dev-tools@1.2.0","@uppy/redux-dev-tools@1.3.0","@uppy/redux-dev-tools@1.3.1","@uppy/redux-dev-tools@1.3.2","@uppy/robodog@0.30.1","@uppy/robodog@0.30.3","@uppy/robodog@0.30.4","@uppy/robodog@0.30.5","@uppy/robodog@1.0.1","@uppy/robodog@1.0.2","@uppy/robodog@1.1.0","@uppy/robodog@1.1.1","@uppy/robodog@1.2.0","@uppy/robodog@1.3.0","@uppy/robodog@1.3.1","@uppy/robodog@1.3.2","@uppy/robodog@1.3.3","@uppy/robodog@1.4.0","@uppy/robodog@1.4.1","@uppy/robodog@1.4.2","@uppy/robodog@1.5.2","@uppy/server-utils@0.26.0","@uppy/status-bar@0.26.0","@uppy/status-bar@0.27.1","@uppy/status-bar@0.27.2","@uppy/status-bar@0.27.3","@uppy/status-bar@0.27.4","@uppy/status-bar@0.28.0","@uppy/status-bar@0.29.0","@uppy/status-bar@0.30.1","@uppy/status-bar@0.30.3","@uppy/status-bar@0.30.4","@uppy/status-bar@0.30.5","@uppy/status-bar@1.0.1","@uppy/status-bar@1.0.2","@uppy/status-bar@1.1.0","@uppy/status-bar@1.2.0","@uppy/status-bar@1.3.0","@uppy/status-bar@1.3.1","@uppy/status-bar@1.4.0","@uppy/status-bar@1.4.1","@uppy/status-bar@1.4.2","@uppy/status-bar@1.5.2","@uppy/store-default@0.26.0","@uppy/store-default@0.28.1","@uppy/store-default@0.28.3","@uppy/store-default@1.1.0","@uppy/store-default@1.2.0","@uppy/store-default@1.2.1","@uppy/store-redux@0.26.0","@uppy/store-redux@0.28.1","@uppy/store-redux@0.28.3","@uppy/store-redux@1.1.0","@uppy/store-redux@1.2.0","@uppy/store-redux@1.2.1","@uppy/thumbnail-generator@0.26.0","@uppy/thumbnail-generator@0.27.1","@uppy/thumbnail-generator@0.27.2","@uppy/thumbnail-generator@0.27.3","@uppy/thumbnail-generator@0.27.4","@uppy/thumbnail-generator@0.28.0","@uppy/thumbnail-generator@0.29.0","@uppy/thumbnail-generator@0.30.1","@uppy/thumbnail-generator@0.30.3","@uppy/thumbnail-generator@0.30.4","@uppy/thumbnail-generator@0.30.5","@uppy/thumbnail-generator@1.0.1","@uppy/thumbnail-generator@1.0.2","@uppy/thumbnail-generator@1.1.0","@uppy/thumbnail-generator@1.2.0","@uppy/thumbnail-generator@1.3.0","@uppy/thumbnail-generator@1.4.0","@uppy/thumbnail-generator@1.5.0","@uppy/thumbnail-generator@1.5.1","@uppy/thumbnail-generator@1.5.2","@uppy/thumbnail-generator@1.5.5","@uppy/transloadit@0.26.0","@uppy/transloadit@0.27.1","@uppy/transloadit@0.27.2","@uppy/transloadit@0.27.3","@uppy/transloadit@0.27.4","@uppy/transloadit@0.27.5","@uppy/transloadit@0.28.0","@uppy/transloadit@0.29.0","@uppy/transloadit@0.30.1","@uppy/transloadit@0.30.3","@uppy/transloadit@0.30.4","@uppy/transloadit@0.30.5","@uppy/transloadit@1.0.1","@uppy/transloadit@1.0.2","@uppy/transloadit@1.1.0","@uppy/transloadit@1.1.1","@uppy/transloadit@1.2.0","@uppy/transloadit@1.3.0","@uppy/transloadit@1.3.1","@uppy/transloadit@1.3.2","@uppy/transloadit@1.4.0","@uppy/transloadit@1.4.1","@uppy/transloadit@1.4.2","@uppy/transloadit@1.5.2","@uppy/tus@0.26.0","@uppy/tus@0.27.1","@uppy/tus@0.27.2","@uppy/tus@0.27.3","@uppy/tus@0.27.4","@uppy/tus@0.27.5","@uppy/tus@0.28.0","@uppy/tus@0.29.0","@uppy/tus@0.30.1","@uppy/tus@0.30.3","@uppy/tus@0.30.4","@uppy/tus@0.30.5","@uppy/tus@1.0.1","@uppy/tus@1.0.2","@uppy/tus@1.1.0","@uppy/tus@1.2.0","@uppy/tus@1.3.0","@uppy/tus@1.4.0","@uppy/tus@1.4.1","@uppy/tus@1.4.2","@uppy/tus@1.5.0","@uppy/tus@1.5.1","@uppy/tus@1.5.2","@uppy/tus@1.5.5","@uppy/url@0.26.0","@uppy/url@0.27.1","@uppy/url@0.27.2","@uppy/url@0.27.3","@uppy/url@0.27.4","@uppy/url@0.27.5","@uppy/url@0.28.0","@uppy/url@0.29.0","@uppy/url@0.30.1","@uppy/url@0.30.3","@uppy/url@0.30.4","@uppy/url@0.30.5","@uppy/url@1.0.1","@uppy/url@1.0.2","@uppy/url@1.1.0","@uppy/url@1.2.0","@uppy/url@1.3.0","@uppy/url@1.3.1","@uppy/url@1.3.2","@uppy/url@1.4.0","@uppy/url@1.4.1","@uppy/url@1.4.2","@uppy/url@1.4.5","@uppy/utils@0.26.0","@uppy/utils@0.27.1","@uppy/utils@0.28.0","@uppy/utils@0.29.0","@uppy/utils@0.30.1","@uppy/utils@0.30.3","@uppy/utils@0.30.4","@uppy/utils@0.30.5","@uppy/utils@0.30.6","@uppy/utils@1.0.2","@uppy/utils@1.1.0","@uppy/utils@1.2.0","@uppy/utils@1.3.0","@uppy/utils@2.0.0","@uppy/utils@2.1.0","@uppy/utils@2.1.1","@uppy/utils@2.1.2","@uppy/utils@2.2.2","@uppy/webcam@0.26.0","@uppy/webcam@0.27.1","@uppy/webcam@0.27.2","@uppy/webcam@0.27.3","@uppy/webcam@0.27.4","@uppy/webcam@0.28.0","@uppy/webcam@0.29.0","@uppy/webcam@0.30.1","@uppy/webcam@0.30.3","@uppy/webcam@0.30.4","@uppy/webcam@0.30.5","@uppy/webcam@1.0.1","@uppy/webcam@1.0.2","@uppy/webcam@1.1.0","@uppy/webcam@1.2.0","@uppy/webcam@1.3.0","@uppy/webcam@1.3.1","@uppy/webcam@1.4.0","@uppy/webcam@1.5.0","@uppy/webcam@1.5.1","@uppy/webcam@1.5.4","@uppy/xhr-upload@0.26.0","@uppy/xhr-upload@0.27.1","@uppy/xhr-upload@0.27.2","@uppy/xhr-upload@0.27.3","@uppy/xhr-upload@0.27.4","@uppy/xhr-upload@0.28.0","@uppy/xhr-upload@0.29.0","@uppy/xhr-upload@0.30.1","@uppy/xhr-upload@0.30.3","@uppy/xhr-upload@0.30.4","@uppy/xhr-upload@0.30.5","@uppy/xhr-upload@1.0.1","@uppy/xhr-upload@1.0.2","@uppy/xhr-upload@1.1.0","@uppy/xhr-upload@1.2.0","@uppy/xhr-upload@1.3.0","@uppy/xhr-upload@1.3.1","@uppy/xhr-upload@1.3.2","@uppy/xhr-upload@1.4.0","@uppy/xhr-upload@1.4.1","@uppy/xhr-upload@1.4.2","@uppy/xhr-upload@1.5.2","uppy@0.26.0","uppy@0.27.1","uppy@0.27.2","uppy@0.27.3","uppy@0.27.4","uppy@0.27.5","uppy@0.28.0","uppy@0.29.0","uppy@0.30.1","uppy@0.30.3","uppy@0.30.4","uppy@0.30.5","uppy@1.0.1","uppy@1.0.2","uppy@1.1.0","uppy@1.2.0","uppy@1.3.0","uppy@1.4.0","uppy@1.5.0","uppy@1.5.1","uppy@1.5.2","uppy@1.6.0","uppy@1.7.0","uppy@1.8.0","uppy@1.9.2","v0.0.2","v0.0.3","v0.0.5","v0.0.6","v0.10.0","v0.10.1","v0.11.0","v0.12.0","v0.12.1","v0.13.0","v0.14.0","v0.14.1","v0.15.0","v0.15.1","v0.15.2","v0.15.3","v0.15.4","v0.15.5","v0.16.0","v0.16.1","v0.16.2","v0.17.0","v0.18.0","v0.18.1","v0.19.0","v0.19.1","v0.20.0","v0.20.1","v0.20.2","v0.20.3","v0.21.0","v0.21.1","v0.22.0","v0.22.1","v0.22.2","v0.22.3","v0.22.5","v0.23.1","v0.23.3","v0.24.0","v0.25.0","v0.25.1","v0.25.2","v0.25.4","v0.25.5","v0.25.6","v0.6.3","v0.6.4","v0.7.0","v0.8.0","v0.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-8135.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}