Description
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.
Remediation
References
https://github.com/unshiftio/url-parse/commit/9be7ee88afd2bb04e4d5a1a8da9a389ac13f8c40
https://huntr.dev/bounties/6d1bc51f-1876-4f5b-a2c2-734e09e8e05b
https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html
Related Vulnerabilities
CVE-2022-0722 Vulnerability in npm package parse-url
CVE-2022-36031 Vulnerability in npm package directus
CVE-2020-15119 Vulnerability in maven package org.webjars.bower:auth0-lock
CVE-2022-25845 Vulnerability in maven package com.alibaba:fastjson
CVE-2018-19586 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web