QID 982670
QID 982670: Nodejs (npm) Security Update for url-parse (GHSA-9m6j-fcg5-2442)
url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9m6j-fcg5-2442 for updates pertaining to this vulnerability.
Vendor References
- GHSA-9m6j-fcg5-2442 -
github.com/advisories/GHSA-9m6j-fcg5-2442
CVEs related to QID 982670
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9m6j-fcg5-2442 | url-parse |
|