CVE-2022-0613
published 2022-02-16CVE-2022-0613: Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
PriorityP335medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.58%
73.1th percentile
Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| medialize | medialize_uri.js | >= unspecified < 1.19.8 | 1.19.8 |
| uri.js_project | uri.js | < 1.19.8 | 1.19.8 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
urijs: Authorization Bypass Through User-Controlled Key
vendor_redhat·2022-02-16·CVSS 6.1
CVE-2022-0613 [MEDIUM] CWE-639 urijs: Authorization Bypass Through User-Controlled Key
urijs: Authorization Bypass Through User-Controlled Key
Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
A flaw was found in urijs due to the fix of CVE-2021-3647 not considering case-sensitive protocol schemes in the URL. This issue allows attackers to bypass the patch.
Package: rh-dotnet50-dotnet (.NET Core 5.0 on Red Hat Enterprise Linux) - Out of support scope
Package: rhacm2/application-ui-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Affected
Package: rhacm2/mcm-topology-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Will not fix
Package: dotnet5.0 (Red Hat Enterprise Linux 8) - Will not fix
Package: quay/quay-rhel8 (Red Hat Quay 3) - Affected
GHSA
Open Redirect in urijs
ghsa·2022-03-07·CVSS 6.5
CVE-2022-0868 [MEDIUM] CWE-601 Open Redirect in urijs
Open Redirect in urijs
urijs prior to version 1.19.10 is vulnerable to open redirect. This is the result of a bypass for the fix to CVE-2022-0613.
OSV
Open Redirect in urijs
osv·2022-03-07·CVSS 6.5
CVE-2022-0868 [MEDIUM] Open Redirect in urijs
Open Redirect in urijs
urijs prior to version 1.19.10 is vulnerable to open redirect. This is the result of a bypass for the fix to CVE-2022-0613.
OSV
Authorization Bypass Through User-Controlled Key in urijs
osv·2022-02-17·CVSS 6.1
CVE-2022-0613 [MEDIUM] Authorization Bypass Through User-Controlled Key in urijs
Authorization Bypass Through User-Controlled Key in urijs
Attacker can use case-insensitive protocol schemes like HTTP, htTP, HTtp etc. in order to bypass the patch for CVE-2021-3647.
GHSA
Authorization Bypass Through User-Controlled Key in urijs
ghsa·2022-02-17·CVSS 6.1
CVE-2022-0613 [MEDIUM] CWE-639 Authorization Bypass Through User-Controlled Key in urijs
Authorization Bypass Through User-Controlled Key in urijs
Attacker can use case-insensitive protocol schemes like HTTP, htTP, HTtp etc. in order to bypass the patch for CVE-2021-3647.
OSV
CVE-2022-0613: Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1
osv·2022-02-16·CVSS 6.5
CVE-2022-0613 [MEDIUM] CVE-2022-0613: Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1
Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/medialize/uri.js/commit/6ea641cc8648b025ed5f30b090c2abd4d1a5249fhttps://huntr.dev/bounties/f53d5c42-c108-40b8-917d-9dad51535083https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MXSSATHALUSXXD2KT6UFZAX7EG4GR332/https://github.com/medialize/uri.js/commit/6ea641cc8648b025ed5f30b090c2abd4d1a5249fhttps://huntr.dev/bounties/f53d5c42-c108-40b8-917d-9dad51535083https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MXSSATHALUSXXD2KT6UFZAX7EG4GR332/
2022-02-16
Published