CVE-2022-0613

Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 30%
Affected Products (NVD)
VendorProductVersion
uri.js_projecturi.js
𝑥
< 1.19.8
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pat
jammy
needs-triage
kinetic
ignored
lunar
ignored
mantic
ignored
noble
needs-triage
trusty
ignored
xenial
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
aspnetcore-runtime-3.1
RHEL 8
0:3.1.24-1.el8_5
fixed
aspnetcore-targeting-pack-3.1
RHEL 8
0:3.1.24-1.el8_5
fixed
dotnet-apphost-pack-3.1
RHEL 8
0:3.1.24-1.el8_5
fixed
dotnet-hostfxr-3.1
RHEL 8
0:3.1.24-1.el8_5
fixed
dotnet-runtime-3.1
RHEL 8
0:3.1.24-1.el8_5
fixed
dotnet-sdk-3.1
RHEL 8
0:3.1.418-1.el8_5
fixed
dotnet-sdk-3.1-source-built-artifacts
RHEL 8
0:3.1.418-1.el8_5
fixed
dotnet-targeting-pack-3.1
RHEL 8
0:3.1.24-1.el8_5
fixed
dotnet-templates-3.1
RHEL 8
0:3.1.418-1.el8_5
fixed