Authorization Bypass Through User-Controlled Key in medialize/uri.js
Published Feb 16, 2022
6.5
MEDIUMCVSS 3.1
EPSS 1.58%
Description
Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<1.19.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Medialize | Medialize/uri.js | n/a |
|
Configuration 1
- < 1.19.8
Configuration 2
- 35
No data.
.NET Core on Red Hat Enterprise Linux
rh-dotnet31-dotnet-0:3.1.418-1.el7_9
Fixed · RHBA-2022:1352
Red Hat Enterprise Linux 8
dotnet3.1-0:3.1.418-1.el8_5
Fixed · RHBA-2022:1386
Red Hat Fuse 7.11.1
urijs
Fixed · RHSA-2022:8652
.NET Core 5.0 on Red Hat Enterprise Linux
rh-dotnet50-dotnet
Out of support scope
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/application-ui-rhel8
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/mcm-topology-rhel8
Will not fix
Red Hat Enterprise Linux 8
dotnet5.0
Will not fix
Red Hat Quay 3
quay/quay-rhel8
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| .NET Core on Red Hat Enterprise Linux | rh-dotnet31-dotnet-0:3.1.418-1.el7_9 | Fixed | RHBA-2022:1352 |
| Red Hat Enterprise Linux 8 | dotnet3.1-0:3.1.418-1.el8_5 | Fixed | RHBA-2022:1386 |
| Red Hat Fuse 7.11.1 | urijs | Fixed | RHSA-2022:8652 |
| .NET Core 5.0 on Red Hat Enterprise Linux | rh-dotnet50-dotnet | Out of support scope | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/application-ui-rhel8 | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/mcm-topology-rhel8 | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | dotnet5.0 | Will not fix | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Affected | n/a |
urijs
npm
Introduced 0 Fixed 1.19.8
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | urijs | 0 | 1.19.8 |
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2022-0613 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2055496 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1011 Advisory
- https://github.com/advisories/GHSA-gcv8-gh4r-25x6 Advisory
- https://github.com/medialize/uri.js/commit/6ea641cc8648b025ed5f30b090c2abd4d1a5249f x_refsource_MISCPatchThird Party Advisory
- https://huntr.dev/bounties/f53d5c42-c108-40b8-917d-9dad51535083 x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MXSSATHALUSXXD2KT6UFZAX7EG4GR332/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MXSSATHALUSXXD2KT6UFZAX7EG4GR332/
- https://nvd.nist.gov/vuln/detail/CVE-2022-0613
- https://www.cve.org/CVERecord?id=CVE-2022-0613
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0613 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2055496 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1011 | Advisory | |
| https://github.com/advisories/GHSA-gcv8-gh4r-25x6 | Advisory | |
| https://github.com/medialize/uri.js/commit/6ea641cc8648b025ed5f30b090c2abd4d1a5249f | x_refsource_MISCPatchThird Party Advisory | |
| https://huntr.dev/bounties/f53d5c42-c108-40b8-917d-9dad51535083 | x_refsource_CONFIRMExploitIssue TrackingPatchThird Party Advisory | |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MXSSATHALUSXXD2KT6UFZAX7EG4GR332/ | vendor-advisoryx_refsource_FEDORA | |
| https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MXSSATHALUSXXD2KT6UFZAX7EG4GR332/ | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-0613 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-0613 |
Change history (0)
No recorded changes yet.