Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

url-parse before 1.5.0 mishandles some http:/ routes as relative urls #608

Closed
znewton opened this issue Feb 25, 2021 · 2 comments
Closed

Comments

@znewton
Copy link

znewton commented Feb 25, 2021

url-parse before 1.5.0 mishandles certain uses of backslash such as http:/ and interprets the URI as a relative path.
CVE-2021-27515

Simple fix would be updating url-parse to 1.5.0

@firefoxNX
Copy link

#607 should resolve this. Can someone please review and merge it?

@xamgore
Copy link
Contributor

xamgore commented Mar 30, 2021

@znewton, I believe the issue can be closed now.

@znewton znewton closed this as completed Sep 10, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants