CVE-2021-27515

Related Vulnerabilities: CVE-2021-27515  

url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.

Description

The MITRE CVE dictionary describes this issue as:

url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.

Additional Information

  • Bugzilla 1934474: CVE-2021-27515 yarnpkg-url-parse: mishandling certain uses of backslash may lead to confidentiality compromise
  • CWE-20: Improper Input Validation
  • FAQ: Frequently asked questions about CVE-2021-27515