CVE-2020-8124

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
04/02/2020
Last modified:
18/02/2020

Description

Insufficient validation and sanitization of user input exists in url-parse npm package version 1.4.4 and earlier may allow attacker to bypass security checks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:url-parse_project:url-parse:*:*:*:*:*:node.js:*:* 1.4.4 (including)


References to Advisories, Solutions, and Tools