5.3

CVE-2021-3664

Exploit

Open Redirect in unshiftio/url-parse

url-parse is vulnerable to URL Redirection to Untrusted Site
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Url-parse ProjectUrl-parse SwPlatformnode.js Version < 1.5.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.83% 0.761
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
security@huntr.dev 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html
https://github.com/unshiftio/url-parse/commit/81ab967889b08112d3356e451bf03e6aa0cbb7e0
Patch
Third Party Advisory
https://huntr.dev/bounties/1625557993985-unshiftio/url-parse
Third Party Advisory
Exploit