url-parse is vulnerable to URL Redirection to Untrusted Site
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://huntr.dev/bounties/1625557993985-unshiftio/url-parse | third party advisory exploit |
https://github.com/unshiftio/url-parse/commit/81ab967889b08112d3356e451bf03e6aa0cbb7e0 | third party advisory patch |
https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html | mailing list |