{"api_version":"1","generated_at":"2026-07-23T11:59:34+00:00","cve":"CVE-2022-24723","urls":{"html":"https://cve.report/CVE-2022-24723","api":"https://cve.report/api/cve/CVE-2022-24723.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-24723","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-24723"},"summary":{"title":"CVE-2022-24723","description":"URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2022-03-03 21:15:00","updated_at":"2023-07-03 20:35:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://github.com/medialize/URI.js/releases/tag/v1.19.9","name":"https://github.com/medialize/URI.js/releases/tag/v1.19.9","refsource":"MISC","tags":[],"title":"Release 1.19.9 (March 3rd 2022) · medialize/URI.js · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/medialize/uri.js/commit/86d10523a6f6e8dc4300d99d671335ee362ad316","name":"https://github.com/medialize/uri.js/commit/86d10523a6f6e8dc4300d99d671335ee362ad316","refsource":"MISC","tags":[],"title":"fix(parse): remove leading whitespace · medialize/URI.js@86d1052 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://huntr.dev/bounties/82ef23b8-7025-49c9-b5fc-1bb9885788e5/","name":"https://huntr.dev/bounties/82ef23b8-7025-49c9-b5fc-1bb9885788e5/","refsource":"MISC","tags":[],"title":"Protocol/Hostname spoofing via Improper Input Validation  vulnerability found in uri.js","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/medialize/URI.js/security/advisories/GHSA-gmv4-r438-p67f","name":"https://github.com/medialize/URI.js/security/advisories/GHSA-gmv4-r438-p67f","refsource":"CONFIRM","tags":[],"title":"Leading white space bypasses protocol validation · Advisory · medialize/URI.js · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-24723","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24723","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"24723","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"uri.js_project","cpe5":"uri.js","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2022","cve_id":"24723","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"urijs_project","cpe5":"urijs","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"node.js","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2022-24723","STATE":"PUBLIC","TITLE":"Improper Input Validation in URI.js"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"URI.js","version":{"version_data":[{"version_value":"< 1.19.9"}]}}]},"vendor_name":"medialize"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This issue has been patched in version 1.19.9. Removing leading whitespace from values before passing them to URI.parse can be used as a workaround."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-20: Improper Input Validation"}]}]},"references":{"reference_data":[{"name":"https://github.com/medialize/URI.js/security/advisories/GHSA-gmv4-r438-p67f","refsource":"CONFIRM","url":"https://github.com/medialize/URI.js/security/advisories/GHSA-gmv4-r438-p67f"},{"name":"https://github.com/medialize/uri.js/commit/86d10523a6f6e8dc4300d99d671335ee362ad316","refsource":"MISC","url":"https://github.com/medialize/uri.js/commit/86d10523a6f6e8dc4300d99d671335ee362ad316"},{"name":"https://github.com/medialize/URI.js/releases/tag/v1.19.9","refsource":"MISC","url":"https://github.com/medialize/URI.js/releases/tag/v1.19.9"},{"name":"https://huntr.dev/bounties/82ef23b8-7025-49c9-b5fc-1bb9885788e5/","refsource":"MISC","url":"https://huntr.dev/bounties/82ef23b8-7025-49c9-b5fc-1bb9885788e5/"}]},"source":{"advisory":"GHSA-gmv4-r438-p67f","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2022-03-03 21:15:00","lastModifiedDate":"2023-07-03 20:35:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:uri.js_project:uri.js:*:*:*:*:*:*:*:*","versionEndExcluding":"1.19.9","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2022","CveId":"24723","Ordinal":"228203","Title":"CVE-2022-24723","CVE":"CVE-2022-24723","Year":"2022"},"notes":[{"CveYear":"2022","CveId":"24723","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}