VDB
KO
MEDIUM

GHSA-h97g-4mx7-5p2p

Open Redirect in apostrophe

Details

Versions of `apostrophe` prior to 2.92.0 are vulnerable to Open Redirect. The package redirected requests to third-party websites if escaped URLs followed by a trailing `/` were appended at the end.

## Recommendation

Update to version 2.92.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / apostrophe
Introduced in: 0 Fixed in: 2.92.0
Fix npm install apostrophe@2.92.0

References