Описание
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| node-url-parse | fixed | 1.5.7-1 | package | |
| node-url-parse | fixed | 1.5.3-1+deb11u2 | bullseye | package |
| node-url-parse | end-of-life | stretch | package |
Примечания
https://huntr.dev/bounties/6d1bc51f-1876-4f5b-a2c2-734e09e8e05b
https://github.com/unshiftio/url-parse/commit/9be7ee88afd2bb04e4d5a1a8da9a389ac13f8c40 (1.5.6)
Связанные уязвимости
CVSS3: 5.3
ubuntu
почти 4 года назад
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.
CVSS3: 8.8
redhat
около 4 лет назад
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.
CVSS3: 5.3
nvd
почти 4 года назад
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.