Опубликовано: 12 авг. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 10
Описание
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 1.2.0-1ubuntu0.1 |
| cosmic | ignored | end of life |
| devel | not-affected | 1.5.10+~1.4.8-3 |
| disco | ignored | end of life |
| eoan | ignored | end of life |
| esm-apps/bionic | released | 1.2.0-1ubuntu0.1 |
| esm-apps/focal | not-affected | 1.4.7-3 |
| esm-apps/jammy | not-affected | 1.5.9+~1.4.8-1 |
| esm-apps/noble | not-affected | 1.5.10+~1.4.8-3 |
| esm-apps/xenial | released | 1.0.5-2ubuntu0.1~esm2 |
Показывать по
10
Ссылки на источники
EPSS
Процентиль: 71%
0.00661
Низкий
7.5 High
CVSS2
10 Critical
CVSS3
Связанные уязвимости
CVSS3: 9.8
redhat
больше 7 лет назад
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
CVSS3: 10
nvd
больше 7 лет назад
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
CVSS3: 10
debian
больше 7 лет назад
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which lea ...
EPSS
Процентиль: 71%
0.00661
Низкий
7.5 High
CVSS2
10 Critical
CVSS3