Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.
References
Link Resource
https://hackerone.com/reports/496293 Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2020-02-04T19:08:56

Updated: 2020-02-04T19:08:56

Reserved: 2020-01-28T00:00:00


Link: CVE-2020-8124

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-02-04T20:15:14.543

Modified: 2020-02-18T15:59:43.253


Link: CVE-2020-8124

JSON object: View

cve-icon Redhat Information

No data.

CWE