Hostname confusion in parse-url
Exposure of Sensitive Information to an Unauthorized Actor via hostname confusion in GitHub repository ionicabizau/parse-url prior to 6.0.1
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
$dependabot rebase will rebase this MR
$dependabot recreate will recreate this MR rewriting all the manual changes and resolving conflicts
Bumps [parse-url](https://github.com/IonicaBizau/parse-url) from 6.0.0 to 6.0.2. **This update includes security fixes.**
<details>
<summary>Vulnerabilities fixed</summary>
<blockquote>
<p><strong>Cross site scripting in parse-url</strong>
Cross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/parse-url prior to 6.0.1</p>
<p>Patched versions: 6.0.1
Affected versions: < 6.0.1</p>
</blockquote>
<blockquote>
<p><strong>Server-Side Request Forgery in parse-url</strong>
Server-Side Request Forgery (SSRF) in GitHub repository ionicabizau/parse-url prior to 7.0.0.</p>
<p>Patched versions: 6.0.1
Affected versions: < 6.0.1</p>
</blockquote>
<blockquote>
<p><strong>Cross site scripting in parse-url</strong>
Cross-site Scripting (XSS) - Stored in GitHub repository ionicabizau/parse-url prior to 7.0.0.</p>
<p>Patched versions: 6.0.1
Affected versions: < 6.0.1</p>
</blockquote>
<blockquote>
<p><strong>Hostname confusion in parse-url</strong>
Exposure of Sensitive Information to an Unauthorized Actor via hostname confusion in GitHub repository ionicabizau/parse-url prior to 6.0.1</p>
<p>Patched versions: 6.0.1
Affected versions: < 6.0.1</p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li>See full diff in <a href="https://github.com/IonicaBizau/parse-url/commits">compare view</a></li>
</ul>
</details>
<br />
---
<details>
<summary>Dependabot commands</summary>
<br />
You can trigger Dependabot actions by commenting on this MR
- `$dependabot rebase` will rebase this MR
- `$dependabot recreate` will recreate this MR rewriting all the manual changes and resolving conflicts
</details>
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Bumps parse-url from 6.0.0 to 6.0.2. This update includes security fixes.
Vulnerabilities fixed
Commits
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
$dependabot rebasewill rebase this MR$dependabot recreatewill recreate this MR rewriting all the manual changes and resolving conflictsadded 2 commits
7aeec8cf- 1 commit from branchmasterCompare with previous version
$dependabot recreate
⚠️
dependabotis recreating merge request. All changes will be overwritten! ⚠️✅
dependabotsuccessfuly recreated merge request!added 2 commits
bcc1ff9b- 1 commit from branchmasterb908a969- Build(deps): [security] bump parse-url from 6.0.0 to 6.0.2Compare with previous version
resolved all threads