CVE-2020-8124

Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.
References
Link Resource
https://hackerone.com/reports/496293 Exploit Third Party Advisory
Configurations

Configuration 1

cpe:2.3:a:url-parse_project:url-parse:*:*:*:*:*:node.js:*:*

Information

Published : 2020-02-04 08:15

Updated : 2020-02-18 03:59


NVD link : CVE-2020-8124

Mitre link : CVE-2020-8124

Products Affected
No products.
CWE