Lack of data validation In parse-url
Description
parse-url parses http URLs incorrectly, making it vulnerable to host name spoofing parse-url prior to 8.1.0 is vulnerable to Misinterpretation of Input. parse-url parses certain http or https URLs incorrectly, identifying the URL's protocol as ssh. It may also parse the host name incorrectly.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
npm | 8.1.0 |
Aliases
1. 2. 3. 4.
References
1. 2.