Junglewise Threat Intelligence

CVE-2022-2218: parse-url cross-site scripting

CVE-2022-2218 · Severity: low · CVSS 3.1 · Published 2022-06-28

Technologies: parse-url (npm). Vendors: npm.

Executive brief

parse-url is a Node.js library that parses and normalizes URLs. The library contained a stored cross-site scripting (XSS) vulnerability that could allow an attacker to inject malicious scripts into web applications using the library, potentially compromising user sessions or stealing sensitive data from users viewing affected pages.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw (CWE-79) in parse-url prior to version 6.0.1. The library failed to properly sanitize or validate user-supplied input when parsing URLs, allowing malicious scripts to be embedded in parsed output. An attacker could craft a malicious URL that, when parsed by the library, would output unsanitized JavaScript code. Applications using parse-url to display user-controlled URLs or to process untrusted URL input are vulnerable. The fix was applied in version 6.0.1, released on 2022-06-27.

Affected products

  • Ionica Bizau parse-url prior to 6.0.1

Timeline

  • 2022-06-28: disclosed: Published to GitHub Advisory Database
  • 2022-06-27: patched: Fix released in version 6.0.1

References

Related threats