Vulnerabilities/

Open Redirect in url-parse

Severity:
High

Description

Versions of url-parse before 1.4.3 returns the wrong hostname which could lead to Open Redirect, Server Side Request Forgery (SSRF), or Bypass Authentication Protocol vulnerabilities.

Recommendation

Update the url-parse package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
url-parse
Anything's wrong? Let us know Last updated on September 11, 2023

This issue is available in SmartScanner Professional

See Pricing