Episode #853 Quiz
URL Parsing Vulnerabilities
Date: 2022-01-11 | Length: 1.5 hrs | Episode page at twit.tv
About this episode
Security researchers from SYNK and Claroty analyzed 16 URL parsers and found eight CVEs caused by inconsistent handling of schemes, slashes, backslashes, encoding, and mixed specifications. Differences between parsers enable SSRF, XSS, open redirects, filter bypasses, DoS, and sometimes RCE. Log4j’s whitelist bypass illustrated the danger, while careful RFC-compliant parsing mitigates it.
Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.