QID 982644
QID 982644: Nodejs (npm) Security Update for google-closure-library (GHSA-vh5w-fg69-rc8m)
A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker to send malicious URLs to be parsed by the library and return the wrong authority. Mitigation -- update your library to version v20200315.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vh5w-fg69-rc8m for updates pertaining to this vulnerability.
Vendor References
- GHSA-vh5w-fg69-rc8m -
github.com/advisories/GHSA-vh5w-fg69-rc8m
CVEs related to QID 982644
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vh5w-fg69-rc8m | google-closure-library |
|