Description
Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.
Remediation
References
https://hackerone.com/reports/496293
Related Vulnerabilities
CVE-2021-23330 Vulnerability in npm package launchpad
CVE-2022-0341 Vulnerability in npm package vditor
CVE-2020-2269 Vulnerability in maven package org.jenkins-ci.plugins:chosen-views-tabbar
CVE-2020-7690 Vulnerability in maven package org.webjars.npm:jspdf
CVE-2022-25758 Vulnerability in maven package org.webjars.npm:scss-tokenizer