GHSA-9q64-mpxx-87fg

Suggest an improvement
Source
https://github.com/advisories/GHSA-9q64-mpxx-87fg
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-9q64-mpxx-87fg/GHSA-9q64-mpxx-87fg.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9q64-mpxx-87fg
Published
2020-04-01T16:35:08Z
Modified
2020-12-15T16:51:18Z
Summary
Open Redirect in ecstatic
Details

Versions of ecstatic prior to 4.1.2, 3.3.2 or 2.2.2 are vulnerable to Open Redirect. The package fails to validate redirects, allowing attackers to craft requests that result in an HTTP 301 redirect to any other domains.

Recommendation

If using ecstatic 4.x, upgrade to 4.1.2 or later. If using ecstatic 3.x, upgrade to 3.3.2 or later. If using ecstatic 2.x, upgrade to 2.2.2 or later.

Database specific
{
    "cwe_ids": [
        "CWE-601"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-04-01T15:37:18Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

npm / ecstatic

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-9q64-mpxx-87fg/GHSA-9q64-mpxx-87fg.json"

npm / ecstatic

Package

Affected ranges

Type
SEMVER
Events
Introduced
3.0.0
Fixed
3.3.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-9q64-mpxx-87fg/GHSA-9q64-mpxx-87fg.json"

npm / ecstatic

Package

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0
Fixed
4.1.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-9q64-mpxx-87fg/GHSA-9q64-mpxx-87fg.json"