Authorization Bypass Through User-Controlled Key in unshiftio/url-parse
Published Feb 17, 2022
6.2
MEDIUMCVSS 3.1
EPSS 1.54%
Description
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.7.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<1.5.7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Unshiftio | Unshiftio/url-Parse | n/a |
|
- < 1.5.7
No data.
Red Hat Migration Toolkit for Containers 1.7
rhmtc/openshift-migration-ui-rhel8:v1.7.4-12
Fixed · RHSA-2022:6429
OpenShift Service Mesh 2.0
servicemesh-grafana
Affected
OpenShift Service Mesh 2.0
servicemesh-prometheus
Affected
OpenShift Service Mesh 2.1
servicemesh-grafana
Will not fix
OpenShift Service Mesh 2.1
servicemesh-prometheus
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
url-parse
Not affected
Red Hat Quay 3
quay/quay-rhel8
Affected
Red Hat Virtualization 4
url-parse
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Migration Toolkit for Containers 1.7 | rhmtc/openshift-migration-ui-rhel8:v1.7.4-12 | Fixed | RHSA-2022:6429 |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-prometheus | Affected | n/a |
| OpenShift Service Mesh 2.1 | servicemesh-grafana | Will not fix | n/a |
| OpenShift Service Mesh 2.1 | servicemesh-prometheus | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | url-parse | Not affected | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Affected | n/a |
| Red Hat Virtualization 4 | url-parse | Not affected | n/a |
url-parse
npm
Introduced 1.0.0 Fixed 1.5.7
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | url-parse | 1.0.0 | 1.5.7 |
Remediation
No remediation recorded yet.
References (10)
- https://access.redhat.com/security/cve/CVE-2022-0639 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2057442 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0924 Advisory
- https://github.com/advisories/GHSA-8v38-pw62-9cw2 Advisory
- https://github.com/unshiftio/url-parse/commit/ef45a1355375a8244063793a19059b4f62fc8788 PatchThird Party Advisory
- https://huntr.dev/bounties/83a6bc9a-b542-4a38-82cd-d995a1481155 ExploitIssue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html mailing-list
- https://lists.debian.org/debian-lts-announce/2025/12/msg00024.html
- https://nvd.nist.gov/vuln/detail/CVE-2022-0639
- https://www.cve.org/CVERecord?id=CVE-2022-0639
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0639 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2057442 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-0924 | Advisory | |
| https://github.com/advisories/GHSA-8v38-pw62-9cw2 | Advisory | |
| https://github.com/unshiftio/url-parse/commit/ef45a1355375a8244063793a19059b4f62fc8788 | PatchThird Party Advisory | |
| https://huntr.dev/bounties/83a6bc9a-b542-4a38-82cd-d995a1481155 | ExploitIssue TrackingPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html | mailing-list | |
| https://lists.debian.org/debian-lts-announce/2025/12/msg00024.html | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-0639 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-0639 |
Change history (0)
No recorded changes yet.