Skip to content
This repository was archived by the owner on Feb 2, 2024. It is now read-only.

Sanitising URL instance parameters #44

Merged
merged 2 commits into from
Dec 9, 2020
Merged

Conversation

jkyberneees
Copy link
Contributor

@jkyberneees jkyberneees commented Dec 8, 2020

Changes:

Notes on the impact:

  • This security issue does NOT impact implementations that rely on fast-gateway, restana or express with prefixed routes such as (app.all('/service', (...))), however it would affect low level implementations such as:
// ...
const service = new http.Server()
service.on('request', (req, res) => {
  proxy(req, res, req.url, {})
})
  • We should deprecate lower versions of this package and recommend upgrade ASAP.

Checklist

@jkyberneees jkyberneees requested a review from mcollina December 8, 2020 14:03
@jkyberneees
Copy link
Contributor Author

Hi @KaixinChen0512, may I kindly ask for your review/comments here as well?
Many thanks in advance.

@jkyberneees jkyberneees changed the title Sanitising URL instances parameters Sanitising URL instance parameters Dec 8, 2020
@KaixinChen0512
Copy link

Hi @KaixinChen0512, may I kindly ask for your review/comments here as well?
Many thanks in advance.

Hi @KaixinChen0512, may I kindly ask for your review/comments here as well?
Many thanks in advance.

sure, my pleasure.

@jkyberneees jkyberneees merged commit f90f26d into master Dec 9, 2020
@jkyberneees jkyberneees deleted the fixing-sec-issue-buildurl branch December 9, 2020 20:51
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants