Arnout Kazemier

2 exploits Active since Aug 2018
CVE-2018-3774 WRITEUP CRITICAL WRITEUP
Url-parse < 1.4.3 - SSRF
Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.
CVSS 10.0
CVE-2021-27515 WRITEUP MEDIUM WRITEUP
url-parse <1.5.0 - Info Disclosure
url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
CVSS 5.3