« Volver al listado

Uri.js Project

Uri.js Project Uri.js: vulnerabilidades y CVE

Uri.js Project Uri.js tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE8
Últimos 12 meses0
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2022-1243Media (6.1)0.67%—5 abr 2022
CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19.11.
CVE-2022-1233Media (6.1)0.80%—4 abr 2022
URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.
CVE-2022-0868Media (6.1)0.72%—6 mar 2022
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.
CVE-2022-24723Media (5.3)1.9%—3 mar 2022
URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version…
CVE-2022-0613Media (6.5)1.6%—16 feb 2022
Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
CVE-2021-3647Media (6.1)0.91%—16 jul 2021
URI.js is vulnerable to URL Redirection to Untrusted Site
CVE-2021-27516Alta (7.5)2.5%—22 feb 2021
URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
CVE-2020-26291Media (6.5)1.7%—31 dic 2020
URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be spoofed by using a backslash (`\`) character followed by an at (`@`) character. If the hostname is…