MEDIUM6.1
GHSA-8h2f-7jc4-7m3m
Open Redirect in urijs
Quick fix
GHSA-8h2f-7jc4-7m3m — urijs: upgrade to the fixed version with the command below.
npm install urijs@1.19.10Details
urijs prior to version 1.19.10 is vulnerable to open redirect. This is the result of a bypass for the fix to CVE-2022-0613.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-0868[ADVISORY]
- https://github.com/medialize/uri.js/commit/a8166fe02f3af6dc1b2b888dcbb807155aad9509[WEB]
- https://github.com/medialize/URI.js/releases/tag/v1.19.10[WEB]
- https://github.com/medialize/uri.js[PACKAGE]
- https://huntr.dev/bounties/5f4db013-64bd-4a6b-9dad-870c296b0b02[WEB]