Back

MEDIUM

nodejs: Hostname spoofing in URL parser for javascript protocol

Published Nov 28, 2018

Description

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Hostname spoofing in URL parser for javascript protocol: If a Node.js application is using url.parse() to determine the URL hostname, that hostname can be spoofed by using a mixed case "javascript:" (e.g. "javAscript:") protocol (other protocols are not affected). If security decisions are made about the URL based on the hostname, they may be incorrect.

Affected products

Remediation

Red Hat statement

The nodejs RPMs shipped in Red Hat OpenShift Container Platform (OCP) versions 3.6 through 3.10 are vulnerable to this flaw because they contain the affected code. Later versions of OCP used nodejs RPMs delivered from Red Hat Software Collections and Red Hat Enterprise Linux channels.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner nodejs
Published Nov 28, 2018
Updated Dec 13, 2024
Reserved Jun 11, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 27, 2018