{"id":"GHSA-9q64-mpxx-87fg","aliases":[],"url":"https://o3.security/vulnerability/GHSA-9q64-mpxx-87fg","summary":"Open Redirect in ecstatic","details":"Versions of `ecstatic` prior to 4.1.2, 3.3.2 or 2.2.2 are vulnerable to Open Redirect. The package fails to validate redirects, allowing attackers to craft requests that result in an `HTTP 301` redirect to any other domains.\n\n\n## Recommendation\n\nIf using `ecstatic` 4.x, upgrade to 4.1.2 or later.\nIf using `ecstatic` 3.x, upgrade to 3.3.2 or later.\nIf using `ecstatic` 2.x, upgrade to 2.2.2 or later.","published":"2020-04-01T16:35:08Z","modified":"2020-12-15T16:51:18Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"ecstatic","fixedVersion":"2.2.2"},{"ecosystem":"npm","name":"ecstatic","fixedVersion":"3.3.2"},{"ecosystem":"npm","name":"ecstatic","fixedVersion":"4.1.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10775"},{"type":"WEB","url":"https://www.npmjs.com/advisories/830"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-12-15T16:51:18Z"}}