MEDIUM6.5
GHSA-gcv8-gh4r-25x6
Authorization Bypass Through User-Controlled Key in urijs
Quick fix
GHSA-gcv8-gh4r-25x6 — urijs: upgrade to the fixed version with the command below.
npm install urijs@1.19.8Details
Attacker can use case-insensitive protocol schemes like HTTP, htTP, HTtp etc. in order to bypass the patch for CVE-2021-3647.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-0613[ADVISORY]
- https://github.com/medialize/uri.js/commit/6ea641cc8648b025ed5f30b090c2abd4d1a5249f[WEB]
- https://github.com/medialize/uri.js[PACKAGE]
- https://huntr.dev/bounties/f53d5c42-c108-40b8-917d-9dad51535083[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MXSSATHALUSXXD2KT6UFZAX7EG4GR332[WEB]