Vulnerabilities/

Authorization Bypass Through User-Controlled Key in urijs

Severity:
Medium

Description

Attacker can use case-insensitive protocol schemes like HTTP, htTP, HTtp etc. in order to bypass the patch for CVE-2021-3647.

Recommendation

Update the urijs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
urijs
Anything's wrong? Let us know Last updated on February 03, 2023

This issue is available in SmartScanner Professional

See Pricing