Lucene search

K
nodejsAhmedNODEJS:678
HistoryAug 02, 2018 - 3:02 p.m.

Open Redirect

2018-08-0215:02:33
Ahmed
www.npmjs.com
565

EPSS

0.003

Percentile

70.5%

Overview

Versions of url-parse before 1.4.3 returns the wrong hostname which could lead to Open Redirect, Server Side Request Forgery (SSRF), or Bypass Authentication Protocol vulnerabilities.

Recommendation

Update to version 1.4.3 or later.

References