First published: Tue Feb 04 2020(Updated: )
Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Url-parse Project Url-parse | <=1.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8124 is a vulnerability in the url-parse npm package version 1.4.4 and earlier that allows an attacker to bypass security checks.
The severity of CVE-2020-8124 is medium with a CVSS score of 5.3.
CVE-2020-8124 affects the url-parse npm package version 1.4.4 and earlier.
An attacker can exploit CVE-2020-8124 by providing insufficiently validated and sanitized user input to bypass security checks.
Yes, upgrading to a version of the url-parse npm package that is later than 1.4.4 will fix CVE-2020-8124.