medialize Vulnerabilities and Affected Products
Vulnerabilities associated with medialize/uri.js.
Products
Clear product- medialize/uri.js5 vulnerabilities
- URI.js2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-1243MEDIUM | CRHTLF can lead to invalid protocol extraction potentially leading to XSS in medialize/uri.jsCRHTLF can lead to invalid protocol extraction potentially leading to XSS in GitHub repository medialize/uri.js prior to 1.19.11. CWE-20Apr 5, 2022 | CVSS6.1v3.1 | EPSS0.663% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-1233MEDIUM | URL Confusion When Scheme Not Supplied in medialize/uri.jsURL Confusion When Scheme Not Supplied in GitHub repository medialize/uri.js prior to 1.19.11. | CVSS6.1v3.1 | EPSS0.787% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0868MEDIUM | Open Redirect in medialize/uri.jsOpen Redirect in GitHub repository medialize/uri.js prior to 1.19.10. CWE-601Mar 6, 2022 | CVSS6.1v3.1 | EPSS0.719% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0613MEDIUM | Authorization Bypass Through User-Controlled Key in medialize/uri.jsAuthorization Bypass Through User-Controlled Key in NPM urijs prior to 1.19.8. CWE-639Feb 16, 2022 | CVSS6.5v3.1 | EPSS1.58% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-3647MEDIUM | Open Redirect in medialize/URI.jsURI.js is vulnerable to URL Redirection to Untrusted Site CWE-601Jul 16, 2021 | CVSS6.1v3.1 | EPSS0.91% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |