CVE-2021-23387
Summary
| CVE | CVE-2021-23387 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-24 19:15:00 UTC |
| Updated | 2021-05-28 14:45:00 UTC |
| Description | The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::createTrailing(), as the web server uses relative URLs instead of absolute URLs. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| fix open redirect (#3) · fardog/trailing-slash@f8e66f1 · GitHub |
MISC |
github.com |
|
| Open Redirect in trailing-slash | Snyk |
MISC |
snyk.io |
|
| github.com/fardog/trailing-slash/blob/f640ece055fe85275c983de5eb94661b95... |
MISC |
github.com |
|
| trailing-slash/index.js at f640ece055fe85275c983de5eb94661b95e35670 · fardog/trailing-slash · GitHub |
MITRE |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: apple502j
Legacy QID Mappings
- 982343 Nodejs (npm) Security Update for trailing-slash (GHSA-rfhr-62xp-2fp2)