Uri.Js

Vendor:

First CVE: Dec 31, 2020 · Active for 5 years

8
Total CVEs
More Total CVEs than 87% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Uri.Js over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2020
5 years ago
Most Recent CVE
Apr 5, 2022
1,574 days ago

CVE Severity & Scoring

Uri.Js8 CVEs
All CVEs352,785 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (50.0%)
Unknown0 (0.0%)
Required4 (50.0%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None7 (87.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
Feb 22, 20217.525NONO
Authorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8.
Feb 16, 20226.524NONO
Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.
Mar 6, 20226.123NONO
URI.js is vulnerable to URL Redirection to Untrusted Site
Jul 16, 20216.122NONO
URI.js is a javascript URL mutation library (npm package urijs). In URI.js before version 1.19.4, the hostname can be spoofed by using a backslash (`\`) character followed by an at
Dec 31, 20206.522NONO
CRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19.11.
Apr 5, 20226.120NONO
URL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11.
Apr 4, 20226.117NONO
URI.js is a Javascript URL mutation library. Before version 1.19.9, whitespace characters are not removed from the beginning of the protocol, so URLs are not parsed properly. This
Mar 3, 20225.316NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Uri.Js

Top CWEs

Versions

No cataloged versions.