You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
https://github.com/delphidabbler/delphidabbler.github.io/security/dependabot/35
The methods URI#join, URI#merge, and URI#+ retained userinfo, such as
user:password, even after the host is replaced. When generating a URL to
a malicious host from a URL containing secret userinfo using these
methods, and having someone access that URL, an unintended userinfo leak
could occur.
0 commit comments