PT-2022-19355 · Parse-Url · Url-Parse

Published

2022-09-14

·

Updated

2022-09-16

·

CVE-2022-2900

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions parse-url versions prior to 8.1.0
Description The issue is related to Server-Side Request Forgery (SSRF) in the GitHub repository ionicabizau/parse-url. SSRF is a type of attack where an attacker can trick a server into making requests to internal or external resources, potentially leading to unauthorized access or data exposure.
Recommendations For versions prior to 8.1.0, update to version 8.1.0 or later to resolve the issue.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-2900
GHSA-J9FQ-VWQV-2FM2

Affected Products

Url-Parse