Описание
Open redirect in url-parse
Overview
Affected versions of npm url-parse are vulnerable to URL Redirection to Untrusted Site.
Impact
Depending on library usage and attacker intent, impacts may include allow/block list bypasses, SSRF attacks, open redirects, or other undesired behavior.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-3664
- https://github.com/unshiftio/url-parse/issues/205
- https://github.com/unshiftio/url-parse/issues/206
- https://github.com/github/advisory-database/pull/6764
- https://github.com/unshiftio/url-parse/commit/81ab967889b08112d3356e451bf03e6aa0cbb7e0
- https://huntr.dev/bounties/1625557993985-unshiftio/url-parse
- https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html
Пакеты
Наименование
url-parse
npm
Затронутые версииВерсия исправления
>= 0.1.0, < 1.5.2
1.5.2
Связанные уязвимости
CVSS3: 5.3
ubuntu
больше 4 лет назад
url-parse is vulnerable to URL Redirection to Untrusted Site
CVSS3: 5.3
redhat
больше 4 лет назад
url-parse is vulnerable to URL Redirection to Untrusted Site
CVSS3: 5.3
nvd
больше 4 лет назад
url-parse is vulnerable to URL Redirection to Untrusted Site
CVSS3: 5.3
debian
больше 4 лет назад
url-parse is vulnerable to URL Redirection to Untrusted Site