You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Feb 18, 2022. It is now read-only.
Affected package: url-parse
Ecosystem: NPM
Affected version range: < 1.5.0
Summary: Path traversal in url-parse
Description: url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
identifiers: [{'type': 'GHSA', 'value': 'GHSA-9m6j-fcg5-2442'}, {'type': 'CVE', 'value': 'CVE-2021-27515'}]
Fixed Version: 1.5.0
Created Date = January 25, 2022
---
Affected package: url-parse
Ecosystem: NPM
Affected version range: < 1.5.2
Summary: Open redirect in url-parse
Description: # Overview
Affected versions of npm url-parse are vulnerable to URL Redirection to Untrusted Site.
Impact
Depending on library usage and attacker intent, impacts may include allow/block list bypasses, SSRF attacks, open redirects, or other undesired behavior.
identifiers: [{'type': 'GHSA', 'value': 'GHSA-hh27-ffr2-f2jc'}, {'type': 'CVE', 'value': 'CVE-2021-3664'}]
Fixed Version: 1.5.2
Created Date = January 25, 2022
---
The text was updated successfully, but these errors were encountered:
Affected versions of npm
url-parse
are vulnerable to URL Redirection to Untrusted Site.Impact
Depending on library usage and attacker intent, impacts may include allow/block list bypasses, SSRF attacks, open redirects, or other undesired behavior.
identifiers: [{'type': 'GHSA', 'value': 'GHSA-hh27-ffr2-f2jc'}, {'type': 'CVE', 'value': 'CVE-2021-3664'}]
The text was updated successfully, but these errors were encountered: