Authorization Bypass Through User-Controlled Key in unshiftio/url-parse
Published Feb 20, 2022
9.1
CRITICALCVSS 3.1
EPSS 1.83%
Description
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.8.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<1.5.8
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Unshiftio | Unshiftio/url-Parse | n/a |
|
- < 1.5.8
No data.
Red Hat Migration Toolkit for Containers 1.7
rhmtc/openshift-migration-ui-rhel8:v1.7.4-12
Fixed · RHSA-2022:6429
OpenShift Service Mesh 2.0
servicemesh-grafana
Affected
OpenShift Service Mesh 2.0
servicemesh-prometheus
Affected
OpenShift Service Mesh 2.1
openshift-service-mesh/kiali-rhel8
Will not fix
OpenShift Service Mesh 2.1
servicemesh-grafana
Will not fix
OpenShift Service Mesh 2.1
servicemesh-prometheus
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
url-parse
Under investigation
Red Hat Quay 3
quay/quay-rhel8
Affected
Red Hat Virtualization 4
url-parse
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Migration Toolkit for Containers 1.7 | rhmtc/openshift-migration-ui-rhel8:v1.7.4-12 | Fixed | RHSA-2022:6429 |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-prometheus | Affected | n/a |
| OpenShift Service Mesh 2.1 | openshift-service-mesh/kiali-rhel8 | Will not fix | n/a |
| OpenShift Service Mesh 2.1 | servicemesh-grafana | Will not fix | n/a |
| OpenShift Service Mesh 2.1 | servicemesh-prometheus | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | url-parse | Under investigation | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Affected | n/a |
| Red Hat Virtualization 4 | url-parse | Not affected | n/a |
url-parse
npm
Introduced 0 Fixed 1.5.8
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | url-parse | 0 | 1.5.8 |
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
AV:N/AC:L/Au:N/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2022-2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 1.83% (0.01827) | 78.09th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.83% (0.01827) | 75.96th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.15% (0.00146) | 32.36th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.22% (0.00219) | 60.82th | v3 (v2023.03.01) |
| May 14, 2024 | 0.16% (0.00163) | 52.65th | v3 (v2023.03.01) |
| Sep 13, 2023 | 0.13% (0.00126) | 46.58th | v3 (v2023.03.01) |
| Aug 3, 2023 | 0.11% (0.00114) | 44.01th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.10% (0.00104) | 41.63th | v3 (v2023.03.01) |
| Mar 25, 2023 | 0.14% (0.00142) | 48.32th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.13% (0.00126) | 45.50th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.02% (0.01018) | 40.58th | v2 (v2022.01.01) |
| Sep 2, 2022 | 0.95% (0.00954) | 34.50th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00954) | 32.50th | v2 (v2022.01.01) |
| Mar 25, 2022 | 0.95% (0.00954) | 17.40th | v2 (v2022.01.01) |
| Feb 21, 2022 | 0.89% (0.00885) | 11.04th | v2 (v2022.01.01) |
References (9)
- https://access.redhat.com/security/cve/CVE-2022-0686 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2060018 Issue Tracking
- https://github.com/advisories/GHSA-hgjh-723h-mx2j Advisory
- https://github.com/unshiftio/url-parse/commit/d5c64791ef496ca5459ae7f2176a31ea53b127e5 PatchThird Party Advisory
- https://huntr.dev/bounties/55fd06cd-9054-4d80-83be-eb5a454be78c ExploitIssue TrackingPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2022-0686
- https://security.netapp.com/advisory/ntap-20220325-0006/ Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-0686
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0686 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2060018 | Issue Tracking | |
| https://github.com/advisories/GHSA-hgjh-723h-mx2j | Advisory | |
| https://github.com/unshiftio/url-parse/commit/d5c64791ef496ca5459ae7f2176a31ea53b127e5 | PatchThird Party Advisory | |
| https://huntr.dev/bounties/55fd06cd-9054-4d80-83be-eb5a454be78c | ExploitIssue TrackingPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html | mailing-list | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0686 | ||
| https://security.netapp.com/advisory/ntap-20220325-0006/ | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-0686 |
Change history (0)
No recorded changes yet.