PT-2022-21170 · Parse-Url · Url-Parse

Published

2022-09-15

·

Updated

2022-09-17

·

CVE-2022-3224

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions parse-url versions prior to 8.1.0
Description The issue concerns a misinterpretation of input in the parse-url library, where certain HTTP or HTTPS URLs are parsed incorrectly. Specifically, the library may identify the URL's protocol as SSH instead of HTTP or HTTPS. Additionally, it may incorrectly parse the host name of the URL.
Recommendations For versions prior to 8.1.0, update to version 8.1.0 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3224
GHSA-PQW5-JMP5-PX4V

Affected Products

Url-Parse