CVE-2022-0613

MEDIUM6.5EPSS 0.12%

Authorization Bypass Through User-Controlled Key in urijs

發布日:2022/2/17修改日:2023/11/8

描述

Attacker can use case-insensitive protocol schemes like HTTP, htTP, HTtp etc. in order to bypass the patch for CVE-2021-3647.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

參考連結(5)