MEDIUM6.1
GHSA-qmm9-x5gr-4gfm
Open Redirect in hekto
Quick fix
GHSA-qmm9-x5gr-4gfm — hekto: upgrade to the fixed version with the command below.
npm install hekto@0.2.4Details
Versions of `hekto` before 0.2.4 are vulnerable to open redirect when a domain name is used as part of the `.html` filename.
## Recommendation
Update to version 0.2.4 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-3743[ADVISORY]
- https://github.com/herber/hekto/pull/3[WEB]
- https://github.com/herber/hekto/commit/1e5c75f8259ba0daf9b2600db3c246cda1934c46[WEB]
- https://hackerone.com/reports/320693[WEB]
- https://github.com/advisories/GHSA-qmm9-x5gr-4gfm[ADVISORY]
- https://www.npmjs.com/advisories/669[WEB]