Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0512

Опубликовано: 07 янв. 2022
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.

An authorization bypass vulnerability was found in nodes-url-parse. This flaw allows a remote attacker with a basic user account to evade hostname verification by inserting the at symbol "@" at the end of the password field. This issue can allow entry to systems designed to block remote access and may not have additional defenses.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Quay 3quay/quay-rhel8Affected
Red Hat Migration Toolkit for Containers 1.7rhmtc/openshift-migration-ui-rhel8FixedRHSA-2022:642913.09.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2054663nodejs-url-parse: authorization bypass through user-controlled key

EPSS

Процентиль: 77%
0.01782
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 4 лет назад

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.

CVSS3: 5.3
nvd
больше 4 лет назад

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.

CVSS3: 5.3
debian
больше 4 лет назад

Authorization Bypass Through User-Controlled Key in NPM url-parse prio ...

CVSS3: 5.3
github
больше 4 лет назад

Authorization bypass in url-parse

EPSS

Процентиль: 77%
0.01782
Низкий

8.8 High

CVSS3