Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29458
HistoryFeb 23, 2021 - 4:45 a.m.

Insecure URL Handling

2021-02-2304:45:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
3
insecure urls
relative path
access controls bypass

EPSS

0.003

Percentile

68.3%

urijs does not securely handle URLs. The backslash is mishandled and causes http:\/ to be interpreted as a relative path. This can potentially result in bypass of access controls.

EPSS

0.003

Percentile

68.3%