Back to bug 1989389

Who When What Removed Added
Dhananjay Arunesh 2021-08-03 06:19:01 UTC Blocks 1989390
Stoyan Nikolov 2021-08-03 07:13:48 UTC Flags needinfo?(darunesh)
Dhananjay Arunesh 2021-08-03 07:30:02 UTC Comment 0 updated
Dhananjay Arunesh 2021-08-03 07:31:36 UTC Flags needinfo?(darunesh)
Dhananjay Arunesh 2021-08-03 07:31:55 UTC Comment 2 updated
Stoyan Nikolov 2021-08-03 07:45:54 UTC Fixed In Version nodejs-url-parse 1.5.2
Red Hat Bugzilla 2021-08-03 07:53:18 UTC Doc Type If docs needed, set a value No Doc Update
Stoyan Nikolov 2021-08-03 08:26:19 UTC CC aileenc, alegrand, amuller, anpicker, aos-bugs, bmontgom, chazlett, drieden, eparis, erooth, ggaughan, gghezzo, gmalinko, gparvin, janstey, jburrell, jochrist, jokerman, jramanat, jross, jwon, kakkoyun, kconner, nstielau, pkrupa, rcernich, rgodfrey, spasquie, sponnaga, stcannon
Stoyan Nikolov 2021-08-03 08:27:46 UTC Fixed In Version nodejs-url-parse 1.5.2 url-parse 1.5.2
Mark Cooper 2021-08-10 00:29:54 UTC Doc Text An input validation flaw exists in the nodejs url-parse library, which incorrectly parses a URL which contains backslashes. An attacker could potentially use this to specify a relative URL and cause the browser to redirect to a malicious website. The highest threat from this vulnerability is to integrity. Related vulnerability is CVE-2021-27515.
RaTasha Tillery-Smith 2021-08-10 17:24:59 UTC Depends On 1992093, 1992095, 1992094
Doc Text An input validation flaw exists in the nodejs url-parse library, which incorrectly parses a URL which contains backslashes. An attacker could potentially use this to specify a relative URL and cause the browser to redirect to a malicious website. The highest threat from this vulnerability is to integrity. Related vulnerability is CVE-2021-27515. An input validation flaw was found in the nodejs url-parse library, which incorrectly parses a URL that contains backslashes. This flaw allows an attacker to specify a relative URL and cause the browser to redirect to a malicious website. The highest threat from this vulnerability is to integrity. Related vulnerability is CVE-2021-27515.
Jon Blackburn 2021-08-12 14:48:08 UTC CC caswilli, kaycoth, rfreiman
CC fjansen, jnakfour, tcarlin, vmugicag
Depends On 1992784, 1992787, 1992785, 1992783, 1992786
CC jblackbu
Red Hat Bugzilla 2021-08-31 22:33:54 UTC Depends On 1995342
CC pkrupa
Red Hat Bugzilla 2021-09-15 05:48:03 UTC CC kakkoyun
Kevan Holdaway 2021-09-30 20:57:57 UTC Depends On 1992819
Red Hat Bugzilla 2021-10-13 10:03:41 UTC CC alegrand
Red Hat Bugzilla 2021-10-15 11:52:00 UTC CC kconner
Red Hat Bugzilla 2022-01-08 05:28:16 UTC CC jokerman
Red Hat Bugzilla 2022-02-22 06:37:20 UTC CC jnakfour
Red Hat Bugzilla 2022-04-19 04:39:03 UTC CC ggaughan
Chess Hazlett 2022-06-13 18:55:52 UTC CC alazarot, anstephe, emingora, etirelli, ibek, jrokos, jstastny, krathod, kverlaen, mnovotny, pjindal, rguimara, rrajasek, tzimanyi
Red Hat Bugzilla 2022-06-30 23:03:17 UTC CC erooth
Red Hat Bugzilla 2022-07-31 22:42:20 UTC CC tzimanyi
Red Hat Bugzilla 2022-08-12 04:30:50 UTC CC amuller
Red Hat Bugzilla 2022-08-12 04:38:14 UTC CC etirelli
Red Hat Bugzilla 2022-10-08 04:27:49 UTC CC gghezzo
Red Hat Bugzilla 2022-10-28 13:13:05 UTC CC krathod
Red Hat Bugzilla 2022-11-14 23:22:48 UTC CC jstastny
Red Hat Bugzilla 2023-05-15 18:03:53 UTC CC rrajasek
Red Hat Bugzilla 2023-05-15 18:09:26 UTC CC drieden
Red Hat Bugzilla 2023-07-07 08:29:07 UTC Assignee security-response-team nobody
Jon Blackburn 2023-07-31 19:09:09 UTC CC jblackbu

Back to bug 1989389