Skip to content

Commit 4f2ae67

Browse files
committedFeb 17, 2022
[security] Add credits for CVE-2022-0639
1 parent 8b3f5f2 commit 4f2ae67

File tree

1 file changed

+12
-0
lines changed

1 file changed

+12
-0
lines changed
 

‎SECURITY.md

+12
Original file line numberDiff line numberDiff line change
@@ -33,6 +33,18 @@ acknowledge your responsible disclosure, if you wish.
3333

3434
## History
3535

36+
> A specially crafted URL with empty userinfo and no host can be used to bypass
37+
> authorization checks.
38+
39+
- **Reporter credits**
40+
- Haxatron
41+
- GitHub: [@haxatron](https://github.com/haxatron)
42+
- Twitter: [@haxatron1](https://twitter.com/haxatron1)
43+
- Huntr report: https://www.huntr.dev/bounties/83a6bc9a-b542-4a38-82cd-d995a1481155/
44+
- Fixed in: 1.5.7
45+
46+
---
47+
3648
> Incorrect handling of username and password can lead to authorization bypass.
3749
3850
- **Reporter credits**

0 commit comments

Comments
 (0)
Please sign in to comment.