Product:

Url\-Parse

(Url\-Parse_project)
Repositories https://github.com/unshiftio/url-parse
#Vulnerabilities 8
Date Id Summary Products Score Patch Annotated
2021-02-22 CVE-2021-27515 url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path. Url\-Parse 5.3
2021-07-26 CVE-2021-3664 url-parse is vulnerable to URL Redirection to Untrusted Site Url\-Parse 5.3
2022-02-14 CVE-2022-0512 Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6. Url\-Parse 5.3
2022-02-17 CVE-2022-0639 Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7. Url\-Parse 5.3
2022-02-20 CVE-2022-0686 Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8. Url\-Parse 9.1
2022-02-21 CVE-2022-0691 Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9. Url\-Parse 9.8
2020-02-04 CVE-2020-8124 Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks. Url\-Parse N/A
2018-08-12 CVE-2018-3774 Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol. Url\-Parse 10.0