url-parse project kayıtları
url-parse project üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-639 Authorization Bypass Through User-Controlled Key4
- CWE-20 Improper Input Validation1
- CWE-425 Direct Request ('Forced Browsing')1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2018-3774İstismar yok | Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Auturl-parse project · url-parse · CWE-425 | Kritik10,0 | — | %3,8 | 12 Ağu 2018 |
40Planlayın | CVE-2022-0691İstismar yok | Authorization Bypass Through User-Controlled Key in unshiftio/url-parseurl-parse project · url-parse · CWE-639 | Kritik9,8 | — | %2,2 | 21 Şub 2022 |
37İzleyin | CVE-2022-0686İstismar yok | Authorization Bypass Through User-Controlled Key in unshiftio/url-parseurl-parse project · url-parse · CWE-639 | Kritik9,1 | — | %1,8 | 20 Şub 2022 |
22İzleyin | CVE-2021-27515İstismar yok | url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.url-parse project · url-parse | Orta5,3 | — | %2,0 | 21 Şub 2021 |
22İzleyin | CVE-2021-3664İstismar yok | Open Redirect in unshiftio/url-parseurl-parse project · url-parse · CWE-601 | Orta5,3 | — | %1,8 | 26 Tem 2021 |
22İzleyin | CVE-2022-0512İstismar yok | Authorization Bypass Through User-Controlled Key in unshiftio/url-parseurl-parse project · url-parse · CWE-639 | Orta5,3 | — | %1,8 | 14 Şub 2022 |
21İzleyin | CVE-2020-8124İstismar yok | Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypasurl-parse project · url-parse · CWE-20 | Orta5,3 | — | %1,7 | 4 Şub 2020 |
21İzleyin | CVE-2022-0639İstismar yok | Authorization Bypass Through User-Controlled Key in unshiftio/url-parseurl-parse project · url-parse · CWE-639 | Orta5,3 | — | %1,5 | 17 Şub 2022 |
- CVE-2018-377441Planlayın
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Aut
KritikCVSS 10,0İstismar yokEPSS %4url-parse project · url-parse12 Ağu 2018
- CVE-2022-069140Planlayın
Authorization Bypass Through User-Controlled Key in unshiftio/url-parse
KritikCVSS 9,8İstismar yokEPSS %2url-parse project · url-parse21 Şub 2022
- CVE-2022-068637İzleyin
Authorization Bypass Through User-Controlled Key in unshiftio/url-parse
KritikCVSS 9,1İstismar yokEPSS %2url-parse project · url-parse20 Şub 2022
- CVE-2021-2751522İzleyin
url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
OrtaCVSS 5,3İstismar yokEPSS %2url-parse project · url-parse21 Şub 2021
- CVE-2021-366422İzleyin
Open Redirect in unshiftio/url-parse
OrtaCVSS 5,3İstismar yokEPSS %2url-parse project · url-parse26 Tem 2021
- CVE-2022-051222İzleyin
Authorization Bypass Through User-Controlled Key in unshiftio/url-parse
OrtaCVSS 5,3İstismar yokEPSS %2url-parse project · url-parse14 Şub 2022
- CVE-2020-812421İzleyin
Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypas
OrtaCVSS 5,3İstismar yokEPSS %2url-parse project · url-parse4 Şub 2020
- CVE-2022-063921İzleyin
Authorization Bypass Through User-Controlled Key in unshiftio/url-parse
OrtaCVSS 5,3İstismar yokEPSS %2url-parse project · url-parse17 Şub 2022