CVE Database
/

CVE-2018-12123

Back to search

CVE-2018-12123

Published: Nov 28, 2018

Modified: Dec 13, 2024

PUBLISHED

Description

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed by using a mixed case "javascript:" (e.g. "javAscript:") protocol (other protocols are not affected). If security decisions are made about the URL based on the hostname, they may be incorrect.

VendorProductVersions

The Node.js Project

Node.js

affected
All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0

Weaknesses (CWE)

References

RHSA-2019:1821
vendor-advisory
x_refsource_REDHAT
GLSA-202003-48
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now