URL Parse
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-3774 | Cri | 0.58 | 10.0 | 0.04 | Aug 12, 2018 | Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol. | ||
| CVE-2022-0691 | Cri | 0.57 | 9.8 | 0.02 | Feb 21, 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9. | ||
| CVE-2022-0639 | Med | 0.28 | 5.3 | 0.02 | Feb 17, 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7. | ||
| CVE-2022-0512 | Med | 0.28 | 5.3 | 0.02 | Feb 14, 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6. | ||
| CVE-2021-27515 | Med | 0.28 | 5.3 | 0.02 | Feb 22, 2021 | url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path. | ||
| CVE-2020-8124 | Med | 0.28 | 5.3 | 0.02 | Feb 4, 2020 | Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks. |
- risk 0.58cvss 10.0epss 0.04
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
- risk 0.57cvss 9.8epss 0.02
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
- risk 0.28cvss 5.3epss 0.02
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.
- risk 0.28cvss 5.3epss 0.02
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.
- risk 0.28cvss 5.3epss 0.02
url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
- risk 0.28cvss 5.3epss 0.02
Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.