Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:7909
HistoryNov 30, 2018 - 5:49 a.m.

Hostname Spoofing

2018-11-3005:49:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
18

EPSS

0.001

Percentile

47.1%

Node.js is vulnerable to hostname spoofing. The hostname can be spoofed using a mixed case Javascript (e.g. javAscript) protocol if the node.js application uses url.parse() to determine the hostname of the URL. This causes hostname-based access controls to be incorrect and allows a remote attacker to bypass such access controls.