Vulnerabilities/

Follow Redirects improperly handles URLs in the url.parse() function

Severity:
Medium

Description

Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname.

Recommendation

Update the follow-redirects package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
follow-redirects
Anything's wrong? Let us know Last updated on January 31, 2024

This issue is available in SmartScanner Professional

See Pricing