VDB
Sign up
CRITICAL10.0

GHSA-pv4c-p2j5-38j4

Open Redirect in url-parse

Quick fix

GHSA-pv4c-p2j5-38j4 — url-parse: upgrade to the fixed version with the command below.

npm install url-parse@1.4.3

Details

Versions of `url-parse` before 1.4.3 returns the wrong hostname which could lead to Open Redirect, Server Side Request Forgery (SSRF), or Bypass Authentication Protocol vulnerabilities.

## Recommendation

Update to version 1.4.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/url-parse
Introduced in: 1.0.0Fixed in: 1.4.3
Fixnpm install url-parse@1.4.3

References