CVE-2022-0613: Authorization Bypass Through User-Controlled Key in medialize/uri.js
A flaw was found in urijs due to the fix of CVE-2021-3647 not considering case-sensitive protocol schemes in the URL. This issue allows attackers to bypass the patch.
Other sources
Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/rh-dotnet31-dotnetto a version that resolves this vulnerability.Fixed in 0:3.1.418-1.el7_9 - Upgrade
Upgrade
redhat/dotnet3.1to a version that resolves this vulnerability.Fixed in 0:3.1.418-1.el8_5 - Upgrade
Upgrade
redhat/urijsto a version that resolves this vulnerability.Fixed in 1.19.8 - Upgrade
Upgrade
medialize/uri.jsto a version that resolves this vulnerability.Fixed in 1.19.8
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-0613?
CVE-2022-0613 is a vulnerability that allows attackers to bypass the patch in urijs prior to version 1.19.8.
What is the severity of CVE-2022-0613?
CVE-2022-0613 has a severity keyword of medium and a severity value of 6.5.
How can I fix CVE-2022-0613?
To fix CVE-2022-0613, update to version 1.19.8 or higher of urijs.
Where can I find more information about CVE-2022-0613?
You can find more information about CVE-2022-0613 at the following references: <ul><li><a href='https://huntr.dev/bounties/f53d5c42-c108-40b8-917d-9dad51535083'>https://huntr.dev/bounties/f53d5c42-c108-40b8-917d-9dad51535083</a></li><li><a href='https://github.com/medialize/uri.js/commit/6ea641cc8648b025ed5f30b090c2abd4d1a5249f'>https://github.com/medialize/uri.js/commit/6ea641cc8648b025ed5f30b090c2abd4d1a5249f</a></li><li><a href='https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2055545'>https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2055545</a></li></ul>
What is the affected software for CVE-2022-0613?
The affected software for CVE-2022-0613 includes urijs prior to version 1.19.8, rh-dotnet31-dotnet version up to exclusive 0:3.1.418-1.el7_9, and dotnet3.1 version up to exclusive 0:3.1.418-1.el8_5.