VDB
Sign up
MEDIUM5.4

GHSA-r773-pmw3-f4mr

Open Redirect in koa-remove-trailing-slashes

Quick fix

GHSA-r773-pmw3-f4mr — koa-remove-trailing-slashes: upgrade to the fixed version with the command below.

npm install koa-remove-trailing-slashes@2.0.2

Details

The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as `https://example.com//attacker.example/`). The vulnerable code is in `index.js::removeTrailingSlashes()`, as the web server uses relative URLs instead of absolute URLs.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/koa-remove-trailing-slashes
Introduced in: 0Fixed in: 2.0.2
Fixnpm install koa-remove-trailing-slashes@2.0.2

References