Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url #21

Open
saberistic opened this issue Oct 19, 2022 · 2 comments

Comments

@saberistic
Copy link

saberistic commented Oct 19, 2022

We are observing following dependency vuln via dependabot. This is a critical vuln

Dependabot cannot update parse-url to a non-vulnerable version
The latest possible version that can be installed is 6.0.5 because of the following conflicting dependencies:

[email protected] requires parse-url@^6.0.0 via a transitive dependency on [email protected]
No patched version available for parse-url
The earliest fixed version is 8.1.0.
@jdnichollsc
Copy link
Contributor

I think it was fixed, right @saberistic?

@saberistic
Copy link
Author

Yes I fixed it in this commit BAXUSNFT@0fdbd79

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants