Authentication Bypass by Spoofing Affecting autolinker package, versions <3.16.1
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-AUTOLINKER-2438289
- published 25 Jul 2022
- disclosed 31 Mar 2022
- credit dbrgn
How to fix?
Upgrade autolinker
to version 3.16.1 or higher.
Overview
autolinker is an Utility to Automatically Link URLs, Email Addresses, Phone Numbers, Twitter handles, and Hashtags in a given block of text/HTML.
Affected versions of this package are vulnerable to Authentication Bypass by Spoofing when a URL
string contains a Unicode RTLO
character, two separate links are generated.
References
CVSS Scores
version 3.1