Description
Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.
Remediation
References
https://hackerone.com/reports/496293
Related Vulnerabilities
CVE-2019-11818 Vulnerability in maven package org.opencms:org.opencms.workplace.tools.accounts
CVE-2021-21347 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2013-2035 Vulnerability in maven package org.fusesource.hawtjni:hawtjni-runtime
CVE-2021-3859 Vulnerability in maven package io.undertow:undertow-core
CVE-2020-15252 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore