-
-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Authorization Bypass in parse-path #109
Labels
Auto Create Issues
Label for Auto Created Issues
do-not-autoclose
Make bot can't close an Issues or PRs
High
This label for Security Severity only
Security
Label for Security Issues
Milestone
Comments
TheKingTermux
added
Security
Label for Security Issues
Auto Create Issues
Label for Auto Created Issues
labels
Aug 15, 2022
Stale issue message |
github-actions
bot
added
the
no-issue-activity
Label for Automatic Bot for Closing the Issues or PRs if not fixed anything in several days
label
Nov 21, 2022
P |
TheKingTermux
removed
the
no-issue-activity
Label for Automatic Bot for Closing the Issues or PRs if not fixed anything in several days
label
Nov 23, 2022
Isu ini sudah tidak ada perkembangan |
github-actions
bot
added
the
no-issue-activity
Label for Automatic Bot for Closing the Issues or PRs if not fixed anything in several days
label
Mar 6, 2023
TheKingTermux
removed
the
no-issue-activity
Label for Automatic Bot for Closing the Issues or PRs if not fixed anything in several days
label
Mar 14, 2023
Isu ini sudah tidak ada perkembangan |
github-actions
bot
added
the
no-issue-activity
Label for Automatic Bot for Closing the Issues or PRs if not fixed anything in several days
label
Jul 9, 2023
TheKingTermux
removed
the
no-issue-activity
Label for Automatic Bot for Closing the Issues or PRs if not fixed anything in several days
label
Jul 17, 2023
Isu ini sudah tidak ada perkembangan |
github-actions
bot
added
the
no-issue-activity
Label for Automatic Bot for Closing the Issues or PRs if not fixed anything in several days
label
Sep 16, 2023
github-actions
bot
removed
the
no-issue-activity
Label for Automatic Bot for Closing the Issues or PRs if not fixed anything in several days
label
Sep 25, 2023
Isu ini sudah tidak ada perkembangan |
github-actions
bot
added
the
no-issue-activity
Label for Automatic Bot for Closing the Issues or PRs if not fixed anything in several days
label
Nov 25, 2023
TheKingTermux
removed
the
no-issue-activity
Label for Automatic Bot for Closing the Issues or PRs if not fixed anything in several days
label
Nov 29, 2023
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
Auto Create Issues
Label for Auto Created Issues
do-not-autoclose
Make bot can't close an Issues or PRs
High
This label for Security Severity only
Security
Label for Security Issues
Description
Authorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0.
Severity Check
Severity Number
7.3
CVSS base metrics
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weaknesses
CWE-639
CVE ID
CVE-2022-0624
GHSA ID
GHSA-3j8f-xvm3-ffx4
Information
Package
parse-path (npm)
Affected versions
< 5.0.0
Patched versions
5.0.0
References
https://nvd.nist.gov/vuln/detail/CVE-2022-0624
IonicaBizau/parse-path@f9ad885
https://huntr.dev/bounties/afffb2bd-fb06-4144-829e-ecbbcbc85388
The text was updated successfully, but these errors were encountered: