Executive brief
URI.js is a JavaScript library used to parse and manipulate URLs in web applications. When parsing URLs without a scheme (protocol) and with excessive slashes like "///www.example.com", the library incorrectly parses the hostname as null instead of recognizing it as a domain, causing the URL to be treated differently than web browsers would. This can lead to unintended redirects or cross-site request forgery (CSRF) attacks if user input is parsed without proper validation.
Technical details
The vulnerability is a URL parsing inconsistency in URI.js versions prior to 1.19.11. When a URL lacks a scheme and contains excessive leading slashes (e.g., "///www.example.com"), the parser incorrectly sets hostname to null and stores the entire path as "/www.example.com", diverging from browser behavior which treats this as an absolute URL to www.example.com. This discrepancy (CWE-115: Misinterpretation of Input, CWE-601: URL Redirection to Untrusted Site) can be exploited by attackers to craft URLs that bypass validation logic or trigger unintended redirects. The vulnerability requires network-accessible application parsing untrusted URLs and is remotely exploitable without authentication. A patch was released in version 1.19.11 addressing the parsing logic for scheme-relative URLs with excessive slashes.
Affected products
- medialize uri.js < 1.19.11
Timeline
- 2022-04-05: disclosed
- 2022-04-05: patched: Fixed in version 1.19.11