Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-8124

Опубликовано: 04 фев. 2020
Источник: debian
EPSS Низкий

Описание

Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-url-parsefixed1.4.7-1package
node-url-parsefixed1.2.0-2+deb10u1busterpackage
node-url-parseignoredstretchpackage

Примечания

  • https://github.com/unshiftio/url-parse/commit/3ecd256f127c3ada36a84d9b8dd3ebd14316274b

  • https://hackerone.com/reports/496293

EPSS

Процентиль: 17%
0.00055
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 6 лет назад

Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.

CVSS3: 5.3
redhat
около 6 лет назад

Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.

CVSS3: 5.3
nvd
около 6 лет назад

Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.

CVSS3: 5.3
github
около 4 лет назад

Improper Validation and Sanitization in url-parse

EPSS

Процентиль: 17%
0.00055
Низкий