Lucene search

K
osvGoogleOSV:GHSA-R773-PMW3-F4MR
HistoryFeb 10, 2022 - 11:47 p.m.

Open Redirect in koa-remove-trailing-slashes

2022-02-1023:47:27
Google
osv.dev
8
open redirect
koa
vulnerability
web server
relative urls

EPSS

0.001

Percentile

40.7%

The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::removeTrailingSlashes(), as the web server uses relative URLs instead of absolute URLs.

EPSS

0.001

Percentile

40.7%

Related for OSV:GHSA-R773-PMW3-F4MR