CVE-2023-26159
Last modified
CVE-2023-26159 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. EPSS estimates a 0.80% chance of exploitation in the next 30 days.
Description
Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site, potentially leading to information disclosure, phishing attacks, or other security breaches.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Follow-Redirects | Follow Redirects | < 1.15.4 |
References
- https://github.com/follow-redirects/follow-redirects/issues/235Exploit, Issue Tracking
- https://github.com/follow-redirects/follow-redirects/pull/236Issue Tracking, Patch
- https://security.snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-6141137Exploit, Third Party Advisory
- https://github.com/follow-redirects/follow-redirects/issues/235Exploit, Issue Tracking
- https://github.com/follow-redirects/follow-redirects/pull/236Issue Tracking, Patch
- https://security.snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-6141137Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-26159?
How severe is CVE-2023-26159?
How do I fix CVE-2023-26159?
Are you affected by CVE-2023-26159?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
