Junglewise Threat Intelligence

CVE-2022-0613: urijs authorization bypass via case-insensitive scheme

CVE-2022-0613 · Severity: low · CVSS 3.1 · Published 2022-02-17

Technologies: urijs (npm). Vendors: npm.

Executive brief

urijs is a JavaScript library for parsing and manipulating URIs. The library failed to handle case-insensitive protocol schemes (HTTP, htTP, HTtp, etc.) when validating URIs, allowing attackers to bypass authorization checks that were previously patched. An attacker could craft URLs with mixed-case schemes to circumvent security controls that depend on protocol validation.

Technical details

The vulnerability is an authorization bypass in urijs due to case-insensitive scheme handling (CWE-639). The library's scheme validation logic was case-sensitive, allowing attackers to bypass security controls implemented in patch CVE-2021-3647 by using mixed-case protocol schemes (e.g., HTTP, htTP) in URIs. No authentication is required; this is a network-reachable vulnerability affecting any application that relies on urijs for URI validation and authorization decisions. An attacker can bypass URL-based access controls, potentially leading to unauthorized access to protected resources. The vulnerability was fixed in version 1.19.8 with a commit implementing case-insensitive scheme parsing.

Affected products

  • urijs before 1.19.8

Timeline

  • 2022-02-17: disclosed
  • 2022-02-17: patched: Fixed in version 1.19.8

References

Related threats