Url-parse Project
Url-parse Project Url-parse: vulnerabilidades y CVE
Url-parse Project Url-parse tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-0691 | Crítica (9.8) | 2.2% | — | 21 feb 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9. |
| CVE-2022-0686 | Crítica (9.1) | 1.8% | — | 20 feb 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8. |
| CVE-2022-0639 | Media (5.3) | 1.5% | — | 17 feb 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7. |
| CVE-2022-0512 | Media (5.3) | 1.8% | — | 14 feb 2022 | Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6. |
| CVE-2021-3664 | Media (5.3) | 1.8% | — | 26 jul 2021 | url-parse is vulnerable to URL Redirection to Untrusted Site |
| CVE-2021-27515 | Media (5.3) | 2.0% | — | 22 feb 2021 | url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path. |
| CVE-2020-8124 | Media (5.3) | 1.7% | — | 4 feb 2020 | Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks. |
| CVE-2018-3774 | Crítica (10) | 3.8% | — | 12 ago 2018 | Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol. |