Vulnerabilities/

Authorization Bypass Through User-Controlled Key in url-parse

Severity:
High

Description

url-parse prior to version 1.5.8 is vulnerable to Authorization Bypass Through User-Controlled Key.

Recommendation

Update the url-parse package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
url-parse
Anything's wrong? Let us know Last updated on November 29, 2023

This issue is available in SmartScanner Professional

See Pricing