Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0613

Опубликовано: 16 фев. 2022
Источник: redhat
CVSS3: 6.5

Описание

Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.

A flaw was found in urijs due to the fix of CVE-2021-3647 not considering case-sensitive protocol schemes in the URL. This issue allows attackers to bypass the patch.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 5.0 on Red Hat Enterprise Linuxrh-dotnet50-dotnetOut of support scope
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/application-ui-rhel8Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/mcm-topology-rhel8Will not fix
Red Hat Enterprise Linux 8dotnet5.0Will not fix
Red Hat Quay 3quay/quay-rhel8Affected
.NET Core on Red Hat Enterprise Linuxrh-dotnet31-dotnetFixedRHBA-2022:135213.04.2022
Red Hat Enterprise Linux 8dotnet3.1FixedRHBA-2022:138618.04.2022
Red Hat Fuse 7.11.1urijsFixedRHSA-2022:865228.11.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2055496urijs: Authorization Bypass Through User-Controlled Key

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.

CVSS3: 6.5
nvd
больше 4 лет назад

Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.

CVSS3: 6.5
debian
больше 4 лет назад

Authorization Bypass Through User-Controlled Key in NPM urijs prior to ...

CVSS3: 6.5
github
больше 4 лет назад

Authorization Bypass Through User-Controlled Key in urijs

6.5 Medium

CVSS3