github.com
https://github.com/IonicaBizau/parse-url CVE-2022-2900
CRITICAL
Server-Side Request Forgery (SSRF) in ionicabizau/parse-url
Record summary
CVE-2022-2900 has a selected CVSS score of 9.1 (critical).
Description
Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 8.1.0.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ionicabizau/parse-urlBrowse ionicabizau / ionicabizau/parse-url | CVE List | Before 8.1.0 | affected |
parse-urlBrowse npm / parse-url | GitHub Advisory | Before 8.1.0 · Fixed in 8.1.0 | affected |
References
4github.com
https://github.com/ionicabizau/parse-url/commit/b88c81df8f4c5168af454eaa4f92afa9349e4e13 huntr.devConfirmation
https://huntr.dev/bounties/1b4c972a-abc8-41eb-a2e1-696db746b5fd nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-2900