You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Vulnerable Package issue exists @ Npm-url-parse-1.4.4 in branch main
Authorization Bypass through User-Controlled Key in NPM url-parse prior to 1.5.7. An incorrect conversion of "@" in protocol in the "href" leads to improper validation of hostname. This issue was reported by @Haxatron through huntr.dev.
Vulnerable Package issue exists @ Npm-url-parse-1.4.4 in branch main
Authorization Bypass through User-Controlled Key in NPM url-parse prior to 1.5.7. An incorrect conversion of "@" in protocol in the "href" leads to improper validation of hostname. This issue was reported by @Haxatron through huntr.dev.
Namespace: Svetlana-github
Repository: test
Repository Url: https://github.com/Svetlana-github/test
CxAST-Project: Svetlana-github/test
CxAST platform scan: 8821ba41-d324-41fa-8053-d13dfc156a43
Branch: main
Application: test
Severity: MEDIUM
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-639
Addition Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: NONE
Availability impact: NONE
Remediation Upgrade Recommendation: 1.5.9
References
Advisory
Commit
Disclosure
Pull request
The text was updated successfully, but these errors were encountered: