Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-27516

Опубликовано: 22 фев. 2021
Источник: redhat
CVSS3: 7.5

Описание

URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:/ and interprets the URI as a relative path.

A flaw was found in nodejs-urijs where URI.js (urijs) mishandles certain uses of the backslash such as http:/ and interprets the URI as a relative path. The highest threat from this vulnerability is to confidentiality.

Отчет

Red Hat Quay includes the urijs dependency in it's package.lock file but it's not used anywhere in the code. Red Hat Advanced Cluster Management for Kubernetes uses Quay as a service, but not code from Quay that exists in RHACM.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/application-ui-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/mcm-topology-rhel8Not affected
Red Hat Quay 3quay/quay-rhel8FixedRHSA-2021:391719.10.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1934470nodejs-urijs: mishandling certain uses of backslash may lead to confidentiality compromise

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.

CVSS3: 7.5
debian
больше 5 лет назад

URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash ...

CVSS3: 7.5
github
больше 5 лет назад

URIjs Hostname spoofing via backslashes in URL

7.5 High

CVSS3