Open Redirect in url-parse
Critical severity
GitHub Reviewed
Published
Aug 13, 2018
to the GitHub Advisory Database
•
Updated Sep 11, 2023
Description
Published to the GitHub Advisory Database
Aug 13, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 11, 2023
Versions of
url-parse
before 1.4.3 returns the wrong hostname which could lead to Open Redirect, Server Side Request Forgery (SSRF), or Bypass Authentication Protocol vulnerabilities.Recommendation
Update to version 1.4.3 or later.
References