Lucene search

K
osvGoogleOSV:GHSA-PV4C-P2J5-38J4
HistoryAug 13, 2018 - 3:02 p.m.

Open Redirect in url-parse

2018-08-1315:02:15
Google
osv.dev
9

EPSS

0.003

Percentile

70.5%

Versions of url-parse before 1.4.3 returns the wrong hostname which could lead to Open Redirect, Server Side Request Forgery (SSRF), or Bypass Authentication Protocol vulnerabilities.

Recommendation

Update to version 1.4.3 or later.