VDB
Sign up
MEDIUM

GHSA-h97g-4mx7-5p2p

Open Redirect in apostrophe

Quick fix

GHSA-h97g-4mx7-5p2p — apostrophe: upgrade to the fixed version with the command below.

npm install apostrophe@2.92.0

Details

Versions of `apostrophe` prior to 2.92.0 are vulnerable to Open Redirect. The package redirected requests to third-party websites if escaped URLs followed by a trailing `/` were appended at the end.

## Recommendation

Update to version 2.92.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/apostrophe
Introduced in: 0Fixed in: 2.92.0
Fixnpm install apostrophe@2.92.0

References