OSV 1.4.0 · github-reviewed · 修改于 2021-05-28 06:38
发布时间
2021-06-09 07:19
GitHub 审查时间
2021-05-28 06:38
NVD 发布时间
2021-05-25 03:15
源文件
advisories/github-reviewed/2021/06/GHSA-rfhr-62xp-2fp2/GHSA-rfhr-62xp-2fp2.json
The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::createTrailing(), as the web server uses relative URLs instead of absolute URLs.