USN-5973-1
Dashboard / Vulnerabilities / USN-5973-1
USN-5973-1
Summary: node-url-parse vulnerabilities
Details: It was discovered that url-parse incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service, or to perform a server-side request forgery attack or open redirect attack. (CVE-2018-3774) It was discovered that url-parse incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to bypass input validation. This issue was only fixed in Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-8124) Yaniv Nizry discovered that url-parse incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service, or to perform a server-side request forgery attack or open redirect attack. This issue was only fixed in Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-27515) It was discovered that url-parse incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service, or to perform a server-side request forgery attack or open redirect attack. This issue was only fixed in Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-3664) It was discovered that url-parse incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to bypass authorization. This issue was only fixed in Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2022-0512, CVE-2022-0639, CVE-2022-0691) Rohan Sharma discovered that url-parse incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to bypass authorization. This issue was only fixed in Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2022-0686)
References: https://ubuntu.com/security/notices/USN-5973-1, https://ubuntu.com/security/CVE-2018-3774, https://ubuntu.com/security/CVE-2020-8124, https://ubuntu.com/security/CVE-2021-3664, https://ubuntu.com/security/CVE-2021-27515, https://ubuntu.com/security/CVE-2022-0512, https://ubuntu.com/security/CVE-2022-0639, https://ubuntu.com/security/CVE-2022-0686, https://ubuntu.com/security/CVE-2022-0691
Affected packages
Package
Name: node-url-parse
Purl: pkg:deb/ubuntu/node-url-parse?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
