CRITICAL10.0
GHSA-pv4c-p2j5-38j4
Open Redirect in url-parse
Quick fix
GHSA-pv4c-p2j5-38j4 — url-parse: upgrade to the fixed version with the command below.
npm install url-parse@1.4.3Details
Versions of `url-parse` before 1.4.3 returns the wrong hostname which could lead to Open Redirect, Server Side Request Forgery (SSRF), or Bypass Authentication Protocol vulnerabilities.
## Recommendation
Update to version 1.4.3 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-3774[ADVISORY]
- https://github.com/unshiftio/url-parse/commit/209c296d302317268afbe19700a70c63ecbeb2d2[WEB]
- https://github.com/unshiftio/url-parse/commit/53b1794e54d0711ceb52505e0f74145270570d5a[WEB]
- https://github.com/unshiftio/url-parse/commit/d7b582ec1243e8024e60ac0b62d2569c939ef5de[WEB]
- https://hackerone.com/reports/384029[WEB]
- https://github.com/unshiftio/url-parse[PACKAGE]
- https://github.com/unshiftio/url-parse/compare/0.2.3...1.0.0[WEB]