Опубликовано: 21 фев. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8
Описание
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | released | 1.2.0-1ubuntu0.1 |
| devel | not-affected | 1.5.10+~1.4.8-2 |
| esm-apps/bionic | released | 1.2.0-1ubuntu0.1 |
| esm-apps/focal | released | 1.4.7-3ubuntu0.1 |
| esm-apps/jammy | not-affected | 1.5.9+~1.4.8-1 |
| esm-apps/xenial | released | 1.0.5-2ubuntu0.1~esm2 |
| focal | released | 1.4.7-3ubuntu0.1 |
| impish | ignored | end of life |
| jammy | not-affected | 1.5.9+~1.4.8-1 |
| kinetic | not-affected | 1.5.10+~1.4.8-2 |
Показывать по
10
EPSS
Процентиль: 30%
0.00109
Низкий
7.5 High
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
CVSS3: 9.8
redhat
почти 4 года назад
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
CVSS3: 9.8
nvd
почти 4 года назад
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
CVSS3: 9.8
debian
почти 4 года назад
Authorization Bypass Through User-Controlled Key in NPM url-parse prio ...
CVSS3: 6.5
github
почти 4 года назад
url-parse incorrectly parses hostname / protocol due to unstripped leading control characters.
EPSS
Процентиль: 30%
0.00109
Низкий
7.5 High
CVSS2
9.8 Critical
CVSS3