Vulnerabilities/

URIjs Hostname spoofing via backslashes in URL

Severity:
High

Description

If using affected versions to determine a URL’s hostname, the hostname can be spoofed by using a backslash (\) character as part of the scheme delimiter, e.g. scheme:/\hostname. If the hostname is used in security decisions, the decision may be incorrect.

Recommendation

Update the urijs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
urijs
Anything's wrong? Let us know Last updated on December 08, 2023

This issue is available in SmartScanner Professional

See Pricing