Affected versions of npm url-parse
are vulnerable to URL Redirection to Untrusted Site.
Depending on library usage and attacker intent, impacts may include allow/block list bypasses, SSRF attacks, open redirects, or other undesired behavior.
github.com/unshiftio/url-parse
github.com/unshiftio/url-parse/commit/81ab967889b08112d3356e451bf03e6aa0cbb7e0
github.com/unshiftio/url-parse/issues/205
github.com/unshiftio/url-parse/issues/206
huntr.dev/bounties/1625557993985-unshiftio/url-parse
lists.debian.org/debian-lts-announce/2023/02/msg00030.html
nvd.nist.gov/vuln/detail/CVE-2021-3664