Junglewise Threat Intelligence

CVE-2022-3224: parse-url hostname spoofing via incorrect URL parsing

CVE-2022-3224 · Severity: low · CVSS 3.1 · Published 2022-09-16

Technologies: parse-url (npm). Vendors: npm.

Executive brief

parse-url is a popular npm library used to parse and normalize URLs in Node.js applications. The library incorrectly parses certain HTTP and HTTPS URLs, misidentifying the protocol as SSH and potentially spoofing hostnames. An attacker could exploit this by crafting malicious URLs to bypass URL validation, redirect traffic to attacker-controlled servers, or trick applications into connecting to wrong hosts.

Technical details

parse-url prior to version 8.1.0 contains a misinterpretation of input vulnerability (CWE-115) in its URL parsing logic. The library fails to correctly parse certain HTTP or HTTPS URLs, sometimes identifying the protocol as SSH instead, and may also parse the hostname incorrectly. The vulnerability is triggered when processing specially crafted URLs and requires no authentication or special privileges. An attacker can exploit this by providing malicious URLs to an application that uses parse-url for validation or redirection, potentially causing hostname spoofing attacks. The fix was released in version 8.1.0.

Affected products

  • Ionic Bizau parse-url prior to 8.1.0

Timeline

  • 2022-09-16: disclosed: Advisory published
  • 2022-09-16: patched: Version 8.1.0 released with fix

References

Related threats