Authentication Bypass by Primary Weakness in org.webjars.npm:parse-url
Cx07b57503-cbc2
- org.webjars.npm:parse-url
- parse-url
Summary
Authentication Bypass by Primary Weakness vulnerability in parse-url. This issue affects versions through 6.0.0, and versions 6.0.2, 6.0.3, 6.0.5.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- NONE
CWE-305 - Authentication Bypass by Primary Weakness
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
References
Advisory Timeline
- Published