First published: Mon Jul 30 2018(Updated: )
A flaw was found in nodejs-url-parse. The wrong hostname can be returned, due to incorrect parsing, which can lead to a variety of vulnerabilities. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
npm/url-parse | <1.4.3 | 1.4.3 |
Url-parse Project Url-parse | <1.4.3 | |
redhat/nodejs-url-parse | <1.4.3 | 1.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3774 is a vulnerability in nodejs-url-parse that can return the wrong hostname due to incorrect parsing.
The severity of CVE-2018-3774 is critical with a severity value of 10.
CVE-2018-3774 can potentially compromise data confidentiality and integrity.
To fix CVE-2018-3774, update the affected software to version 1.4.3.
You can find more information about CVE-2018-3774 from the CVE website and the NVD website.