CVE Vulnerabilities

CVE-2018-3774

Direct Request ('Forced Browsing')

Published: Aug 12, 2018 | Modified: Nov 21, 2024
CVSS 3.x
10
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
9.8 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Incorrect parsing in url-parse <1.4.3 returns wrong hostname which leads to multiple vulnerabilities such as SSRF, Open Redirect, Bypass Authentication Protocol.

Weakness

The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.

Affected Software

NameVendorStart VersionEnd Version
Url-parseUrl-parse_project*1.4.3 (excluding)
Red Hat Quay 3RedHatquay/quay-rhel8:v3.6.0-62*
Node-url-parseUbuntubionic*
Node-url-parseUbuntucosmic*
Node-url-parseUbuntudisco*
Node-url-parseUbuntueoan*
Node-url-parseUbuntuesm-apps/bionic*
Node-url-parseUbuntuesm-apps/xenial*
Node-url-parseUbuntugroovy*
Node-url-parseUbuntuhirsute*
Node-url-parseUbuntuimpish*
Node-url-parseUbuntulunar*
Node-url-parseUbuntumantic*
Node-url-parseUbuntuupstream*
Node-url-parseUbuntuxenial*

Potential Mitigations

References