First published: Mon Jul 26 2021(Updated: )
url-parse is vulnerable to URL Redirection to Untrusted Site
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Url-parse Project Url-parse | <1.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3664 is a vulnerability in url-parse that allows for URL redirection to untrusted sites.
The severity of CVE-2021-3664 is medium with a CVSS score of 5.3.
The affected software is url-parse version up to exclusive 1.5.2 in the Node.js environment.
To fix CVE-2021-3664, update url-parse to a version higher than 1.5.2.
More information about CVE-2021-3664 can be found at the following references: [Reference 1](https://github.com/unshiftio/url-parse/commit/81ab967889b08112d3356e451bf03e6aa0cbb7e0), [Reference 2](https://huntr.dev/bounties/1625557993985-unshiftio/url-parse), [Reference 3](https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html).