{"id":"GHSA-9q64-mpxx-87fg","summary":"Open Redirect in ecstatic","details":"Versions of `ecstatic` prior to 4.1.2, 3.3.2 or 2.2.2 are vulnerable to Open Redirect. The package fails to validate redirects, allowing attackers to craft requests that result in an `HTTP 301` redirect to any other domains.\n\n\n## Recommendation\n\nIf using `ecstatic` 4.x, upgrade to 4.1.2 or later.\nIf using `ecstatic` 3.x, upgrade to 3.3.2 or later.\nIf using `ecstatic` 2.x, upgrade to 2.2.2 or later.","modified":"2020-12-15T16:51:18Z","published":"2020-04-01T16:35:08Z","database_specific":{"github_reviewed_at":"2020-04-01T15:37:18Z","nvd_published_at":null,"cwe_ids":["CWE-601"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10775"},{"type":"WEB","url":"https://www.npmjs.com/advisories/830"}],"affected":[{"package":{"name":"ecstatic","ecosystem":"npm","purl":"pkg:npm/ecstatic"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.2.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-9q64-mpxx-87fg/GHSA-9q64-mpxx-87fg.json"}},{"package":{"name":"ecstatic","ecosystem":"npm","purl":"pkg:npm/ecstatic"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.3.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-9q64-mpxx-87fg/GHSA-9q64-mpxx-87fg.json"}},{"package":{"name":"ecstatic","ecosystem":"npm","purl":"pkg:npm/ecstatic"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-9q64-mpxx-87fg/GHSA-9q64-mpxx-87fg.json"}}],"schema_version":"1.9.0"}