Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-0613

Опубликовано: 16 фев. 2022
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.

A flaw was found in urijs due to the fix of CVE-2021-3647 not considering case-sensitive protocol schemes in the URL. This issue allows attackers to bypass the patch.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
.NET Core 5.0 on Red Hat Enterprise Linuxrh-dotnet50-dotnetOut of support scope
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/mcm-topology-rhel8Will not fix
Red Hat Enterprise Linux 8dotnet5.0Will not fix
Red Hat Quay 3quay/quay-rhel8Affected
.NET Core on Red Hat Enterprise Linuxrh-dotnet31-dotnetFixedRHBA-2022:135213.04.2022
Red Hat Advanced Cluster Management for Kubernetes 2acm-grafana-containerFixedRHSA-2022:168103.05.2022
Red Hat Advanced Cluster Management for Kubernetes 2acm-must-gather-containerFixedRHSA-2022:168103.05.2022
Red Hat Advanced Cluster Management for Kubernetes 2acm-operator-bundle-containerFixedRHSA-2022:168103.05.2022
Red Hat Advanced Cluster Management for Kubernetes 2application-ui-containerFixedRHSA-2022:168103.05.2022
Red Hat Advanced Cluster Management for Kubernetes 2assisted-image-service-containerFixedRHSA-2022:168103.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-178->CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2055496urijs: Authorization Bypass Through User-Controlled Key

EPSS

Процентиль: 31%
0.00119
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 4 года назад

Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.

CVSS3: 6.5
nvd
почти 4 года назад

Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.

CVSS3: 6.5
debian
почти 4 года назад

Authorization Bypass Through User-Controlled Key in NPM urijs prior to ...

CVSS3: 6.5
github
почти 4 года назад

Authorization Bypass Through User-Controlled Key in urijs

EPSS

Процентиль: 31%
0.00119
Низкий

6.5 Medium

CVSS3