Vulnerabilities/

URIjs Vulnerable to Hostname spoofing via backslashes in URL

Severity:
Medium

Description

If using affected versions to determine a URL’s hostname, the hostname can be spoofed by using a combination of backslash (\) and slash (/) characters as part of the scheme delimiter, e.g. scheme:/\/\/\hostname. If the hostname is used in security decisions, the decision may be incorrect.

Recommendation

Update the urijs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
urijs
Anything's wrong? Let us know Last updated on September 07, 2023

This issue is available in SmartScanner Professional

See Pricing