CVE-2022-24723
Summary
| CVE | CVE-2022-24723 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-03 21:15:00 UTC |
| Updated | 2023-07-03 20:35:00 UTC |
| Description | URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Uri.js Project | Uri.js | All | All | All | All |
| Application | Urijs Project | Urijs | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release 1.19.9 (March 3rd 2022) · medialize/URI.js · GitHub | MISC | github.com | |
| fix(parse): remove leading whitespace · medialize/URI.js@86d1052 · GitHub | MISC | github.com | |
| Protocol/Hostname spoofing via Improper Input Validation vulnerability found in uri.js | MISC | huntr.dev | |
| Leading white space bypasses protocol validation · Advisory · medialize/URI.js · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.