MEDIUM6.1
GHSA-hh27-ffr2-f2jc
Open redirect in url-parse
Quick fix
GHSA-hh27-ffr2-f2jc — url-parse: upgrade to the fixed version with the command below.
npm install url-parse@1.5.2Details
# Overview
Affected versions of npm `url-parse` are vulnerable to URL Redirection to Untrusted Site.
# Impact
Depending on library usage and attacker intent, impacts may include allow/block list bypasses, SSRF attacks, open redirects, or other undesired behavior.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-3664[ADVISORY]
- https://github.com/unshiftio/url-parse/issues/205[WEB]
- https://github.com/unshiftio/url-parse/issues/206[WEB]
- https://github.com/github/advisory-database/pull/6764[WEB]
- https://github.com/unshiftio/url-parse/commit/81ab967889b08112d3356e451bf03e6aa0cbb7e0[WEB]
- https://github.com/unshiftio/url-parse[PACKAGE]
- https://huntr.dev/bounties/1625557993985-unshiftio/url-parse[WEB]
- https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html[WEB]