Authorization Bypass Through User-Controlled Key in unshiftio/url-parse
Published Feb 21, 2022
9.8
CRITICALCVSS 3.1
EPSS 2.22%
Description
Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.9.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<1.5.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Unshiftio | Unshiftio/url-Parse | n/a |
|
- < 1.5.9
No data.
Red Hat Migration Toolkit for Containers 1.7
rhmtc/openshift-migration-ui-rhel8:v1.7.4-12
Fixed · RHSA-2022:6429
OpenShift Service Mesh 2.0
servicemesh-grafana
Affected
OpenShift Service Mesh 2.0
servicemesh-prometheus
Affected
OpenShift Service Mesh 2.1
servicemesh-grafana
Affected
OpenShift Service Mesh 2.1
servicemesh-prometheus
Affected
Red Hat Advanced Cluster Management for Kubernetes 2
url-parse
Under investigation
Red Hat Quay 3
quay/quay-rhel8
Affected
Red Hat Virtualization 4
url-parse
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Migration Toolkit for Containers 1.7 | rhmtc/openshift-migration-ui-rhel8:v1.7.4-12 | Fixed | RHSA-2022:6429 |
| OpenShift Service Mesh 2.0 | servicemesh-grafana | Affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh-prometheus | Affected | n/a |
| OpenShift Service Mesh 2.1 | servicemesh-grafana | Affected | n/a |
| OpenShift Service Mesh 2.1 | servicemesh-prometheus | Affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | url-parse | Under investigation | n/a |
| Red Hat Quay 3 | quay/quay-rhel8 | Affected | n/a |
| Red Hat Virtualization 4 | url-parse | Not affected | n/a |
url-parse
npm
Introduced 0.1.0 Fixed 1.5.9
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | url-parse | 0.1.0 | 1.5.9 |
Remediation
No remediation recorded yet.
References (11)
- https://access.redhat.com/security/cve/CVE-2022-0691 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2060020 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1074 Advisory
- https://github.com/advisories/GHSA-jf5r-8hm2-f872 Advisory
- https://github.com/github/advisory-database/pull/6765
- https://github.com/unshiftio/url-parse/commit/0e3fb542d60ddbf6933f22eb9b1e06e25eaa5b63 PatchThird Party Advisory
- https://huntr.dev/bounties/57124ed5-4b68-4934-8325-2c546257f2e4 ExploitPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2022-0691
- https://security.netapp.com/advisory/ntap-20220325-0006 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2022-0691
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-0691 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2060020 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1074 | Advisory | |
| https://github.com/advisories/GHSA-jf5r-8hm2-f872 | Advisory | |
| https://github.com/github/advisory-database/pull/6765 | ||
| https://github.com/unshiftio/url-parse/commit/0e3fb542d60ddbf6933f22eb9b1e06e25eaa5b63 | PatchThird Party Advisory | |
| https://huntr.dev/bounties/57124ed5-4b68-4934-8325-2c546257f2e4 | ExploitPatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2023/02/msg00030.html | mailing-list | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-0691 | ||
| https://security.netapp.com/advisory/ntap-20220325-0006 | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2022-0691 |
Change history (0)
No recorded changes yet.