VDB
Sign up
MEDIUM6.1

GHSA-hh27-ffr2-f2jc

Open redirect in url-parse

Quick fix

GHSA-hh27-ffr2-f2jc — url-parse: upgrade to the fixed version with the command below.

npm install url-parse@1.5.2

Details

# Overview

Affected versions of npm `url-parse` are vulnerable to URL Redirection to Untrusted Site.

# Impact

Depending on library usage and attacker intent, impacts may include allow/block list bypasses, SSRF attacks, open redirects, or other undesired behavior.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/url-parse
Introduced in: 0.1.0Fixed in: 1.5.2
Fixnpm install url-parse@1.5.2

References