CVE-2020-8124: Input Validation
Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
url-parse npm packageto a version that resolves this vulnerability.Fixed in 1.4.4
Event History
Frequently Asked Questions
What is CVE-2020-8124?
CVE-2020-8124 is a vulnerability in the url-parse npm package version 1.4.4 and earlier that allows an attacker to bypass security checks.
What is the severity of CVE-2020-8124?
The severity of CVE-2020-8124 is medium with a CVSS score of 5.3.
How does CVE-2020-8124 affect software?
CVE-2020-8124 affects the url-parse npm package version 1.4.4 and earlier.
How can an attacker exploit CVE-2020-8124?
An attacker can exploit CVE-2020-8124 by providing insufficiently validated and sanitized user input to bypass security checks.
Is there a fix for CVE-2020-8124?
Yes, upgrading to a version of the url-parse npm package that is later than 1.4.4 will fix CVE-2020-8124.