MEDIUM5.3
GHSA-rqff-837h-mm52
Authorization bypass in url-parse
Quick fix
GHSA-rqff-837h-mm52 — url-parse: upgrade to the fixed version with the command below.
npm install url-parse@1.5.6Details
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-0512[ADVISORY]
- https://github.com/unshiftio/url-parse/commit/9be7ee88afd2bb04e4d5a1a8da9a389ac13f8c40[WEB]
- https://github.com/unshiftio/url-parse[PACKAGE]
- https://huntr.dev/bounties/6d1bc51f-1876-4f5b-a2c2-734e09e8e05b[WEB]
- https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html[WEB]