Vulnerabilities/

Hostname spoofing via backslashes in URL

Severity:
Medium

Description

If using affected versions to determine a URL’s hostname, the hostname can be spoofed by using a backslash (\) character followed by an at (@) character. If the hostname is used in security decisions, the decision may be incorrect.

Recommendation

Update the urijs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
urijs
Anything's wrong? Let us know Last updated on February 01, 2023

This issue is available in SmartScanner Professional

See Pricing