Update bitlyshortener to >=0.5.0 to prevent generating some invalid short URLs
High severity
GitHub Reviewed
Published
Oct 23, 2020
in
impredicative/bitlyshortener
•
Updated Jan 9, 2023
Description
Reviewed
Oct 27, 2020
Published to the GitHub Advisory Database
Oct 27, 2020
Last updated
Jan 9, 2023
Impact
Due to a sudden upstream breaking change by Bitly, versions of
bitlyshortener
<0.5.0 can generate an invalid short URL when a vanity domain exists.Patches
Upgrading
bitlyshortener
to 0.5.0 or newer will prevent the generation of any such invalid short URLs.References
References