Skip to main content

Authentication Bypass by Primary Weakness in org.webjars.npm:parse-url

Cx07b57503-cbc2

  • org.webjars.npm:parse-url
  • parse-url
Severity High
Score 9.1/10

Summary

Authentication Bypass by Primary Weakness vulnerability in parse-url. This issue affects versions through 6.0.0, and versions 6.0.2, 6.0.3, 6.0.5.

  • LOW
  • NETWORK
  • HIGH
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-305 - Authentication Bypass by Primary Weakness

The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.

Advisory Timeline

  • Published