CVE-2021-3664: Open Redirect in unshiftio/url-parse
Published Jul 26, 2021
·Updated
url-parse is vulnerable to URL Redirection to Untrusted Site
Affected Software
1 affected component
Url-parse Project Url-parse Node.js<1.5.2
Remediation
Event History
Jul 26, 2021
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-3664?
CVE-2021-3664 is a vulnerability in url-parse that allows for URL redirection to untrusted sites.
2
What is the severity of CVE-2021-3664?
The severity of CVE-2021-3664 is medium with a CVSS score of 5.3.
3
Which software is affected by CVE-2021-3664?
The affected software is url-parse version up to exclusive 1.5.2 in the Node.js environment.
4
How can I fix CVE-2021-3664?
To fix CVE-2021-3664, update url-parse to a version higher than 1.5.2.
5
Where can I find more information about CVE-2021-3664?
More information about CVE-2021-3664 can be found at the following references: [Reference 1](https://github.com/unshiftio/url-parse/commit/81ab967889b08112d3356e451bf03e6aa0cbb7e0), [Reference 2](https://huntr.dev/bounties/1625557993985-unshiftio/url-parse), [Reference 3](https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html).