CRITICAL9.1
GHSA-hgjh-723h-mx2j
Authorization Bypass Through User-Controlled Key in url-parse
Quick fix
GHSA-hgjh-723h-mx2j — url-parse: upgrade to the fixed version with the command below.
npm install url-parse@1.5.8Details
url-parse prior to version 1.5.8 is vulnerable to Authorization Bypass Through User-Controlled Key.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-0686[ADVISORY]
- https://github.com/unshiftio/url-parse/commit/d5c64791ef496ca5459ae7f2176a31ea53b127e5[WEB]
- https://github.com/unshiftio/url-parse[PACKAGE]
- https://huntr.dev/bounties/55fd06cd-9054-4d80-83be-eb5a454be78c[WEB]
- https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html[WEB]
- https://security.netapp.com/advisory/ntap-20220325-0006[WEB]