PT-2018-16192 · Npm+2 · Url-Parse+2

·

CVE-2018-3774

·

Published

2018-08-12

·

Updated

2023-03-27

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions url-parse versions prior to 1.4.3
Description The issue is related to incorrect parsing in url-parse, which returns the wrong hostname. This can lead to multiple vulnerabilities, including Server Side Request Forgery (SSRF), Open Redirect, and Bypass Authentication Protocol.
Recommendations Update to version 1.4.3 or later.

Fix

Open Redirect

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-3774
GHSA-PV4C-P2J5-38J4
USN-5973-1

Affected Products

Linuxmint
Ubuntu
Url-Parse