QID 982343
QID 982343: Nodejs (npm) Security Update for trailing-slash (GHSA-rfhr-62xp-2fp2)
The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::createTrailing(), as the web server uses relative URLs instead of absolute URLs.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-rfhr-62xp-2fp2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-rfhr-62xp-2fp2 -
github.com/advisories/GHSA-rfhr-62xp-2fp2
CVEs related to QID 982343
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-rfhr-62xp-2fp2 | trailing-slash |
|