Vulnerability Database
Blog
FAQ
Docs
CVE-2022-2900
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2022-2900
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2900.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-2900
Aliases
GHSA-j9fq-vwqv-2fm2
Published
2022-09-14T11:15:47Z
Modified
2025-01-15T02:19:55.189660Z
Severity
9.1 (Critical)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Calculator
Summary
[none]
Details
Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 8.1.0.
References
https://huntr.dev/bounties/1b4c972a-abc8-41eb-a2e1-696db746b5fd
https://github.com/ionicabizau/parse-url/commit/b88c81df8f4c5168af454eaa4f92afa9349e4e13
Affected packages
Git
/
github.com/ionicabizau/parse-url
Affected ranges
Type
GIT
Repo
https://github.com/ionicabizau/parse-url
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
b88c81df8f4c5168af454eaa4f92afa9349e4e13
Fixed
b88c81df8f4c5168af454eaa4f92afa9349e4e13
Affected versions
3.*
3.0.0
3.0.1
3.0.2
4.*
4.0.0
5.*
5.0.0
5.0.1
5.0.2
5.0.3
5.0.5
5.0.6
5.0.8
6.*
6.0.0
6.0.1
6.0.5
7.*
7.0.0
7.0.1
7.0.2
CVE-2022-2900 - OSV