url-parse : < 1.5.8 - Authorization Bypass Through User-Controlled Key in url-parse
Created by: armorcodegithubqa[bot]
url-parse prior to version 1.5.8 is vulnerable to Authorization Bypass Through User-Controlled Key.
References:
- https://nvd.nist.gov/vuln/detail/CVE-2022-0686
- https://github.com/unshiftio/url-parse/commit/d5c64791ef496ca5459ae7f2176a31ea53b127e5
- https://huntr.dev/bounties/55fd06cd-9054-4d80-83be-eb5a454be78c
- https://github.com/advisories/GHSA-hgjh-723h-mx2j
File Path: public/package-lock.json
Mitigation: Patched version: 1.5.8