got (JS Package) <= 11.8.4 and 12.0-<12.1.0 - Open Redirect
mediumThe got (JS Package) is vulnerable to Open Redirect in versions up to, and including, 11.8.4 as well as from 12 to below 12.1.0. Requested URLs are not verified and allow open redirection to a local UNIX socket.
- CVSS:
- 5.3
- Affected:
- up to 1.11.1
- Fixed in:
- 2.0.0
- Disclosed:
- Jun 19, 2022