PT-2022-15277 · Parse-Url · Url-Parse

Published

2022-06-27

·

Updated

2023-12-15

·

CVE-2022-2216

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions parse-url versions prior to 7.0.0
Description The issue is related to Server-Side Request Forgery (SSRF) in the parse-url repository. This allows for the exploitation of parse URL to read local files.
Recommendations For versions prior to 7.0.0, update to version 7.0.0 or later to resolve the issue.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-2216
GHSA-7F3X-X4PR-WQHJ

Affected Products

Url-Parse