Description
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
Remediation
References
https://hackerone.com/reports/384029
https://github.com/unshiftio/url-parse/commit/d7b582ec1243e8024e60ac0b62d2569c939ef5de
https://github.com/unshiftio/url-parse/commit/53b1794e54d0711ceb52505e0f74145270570d5a
Related Vulnerabilities
CVE-2022-4350 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2023-46122 Vulnerability in maven package org.scala-sbt:io_2.13
CVE-2021-3801 Vulnerability in npm package prismjs
CVE-2020-2176 Vulnerability in maven package it.infuse.jenkins:usemango-runner
CVE-2023-24815 Vulnerability in maven package io.vertx:vertx-web