Uri.js Project
Uri.js Project Uri.js: vulnerabilidades y CVE
Uri.js Project Uri.js tiene 8 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-1243 | Media (6.1) | 0.67% | — | 5 abr 2022 | CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19.11. |
| CVE-2022-1233 | Media (6.1) | 0.80% | — | 4 abr 2022 | URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11. |
| CVE-2022-0868 | Media (6.1) | 0.72% | — | 6 mar 2022 | Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10. |
| CVE-2022-24723 | Media (5.3) | 1.9% | — | 3 mar 2022 | URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version… |
| CVE-2022-0613 | Media (6.5) | 1.6% | — | 16 feb 2022 | Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8. |
| CVE-2021-3647 | Media (6.1) | 0.91% | — | 16 jul 2021 | URI.js is vulnerable to URL Redirection to Untrusted Site |
| CVE-2021-27516 | Alta (7.5) | 2.5% | — | 22 feb 2021 | URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path. |
| CVE-2020-26291 | Media (6.5) | 1.7% | — | 31 dic 2020 | URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be spoofed by using a backslash (`\`) character followed by an at (`@`) character. If the hostname is… |