Invalid URL generation in bitlyshortener
Moderate severity
GitHub Reviewed
Published
Jan 19, 2022
in
impredicative/bitlyshortener
•
Updated Jan 11, 2023
Description
Reviewed
Jan 20, 2022
Published to the GitHub Advisory Database
Jan 21, 2022
Last updated
Jan 11, 2023
Impact
Due to a sudden upstream breaking change by Bitly, versions of
bitlyshortener
<0.6.0 generate invalid short URLs. All users are affected and must update immediately.Patches
Upgrading
bitlyshortener
to 0.6.0 or newer will prevent the generation such invalid short URLs.Workarounds
A workaround is to replace "https://j.mp/" in each generated short URL with "https://bit.ly/".
References
References