Junglewise Threat Intelligence

CVE-2022-1233: medialize uri.js URL confusion with missing scheme

CVE-2022-1233 · Severity: low · CVSS 3 · Published 2022-04-05

Technologies: urijs (npm), Medialize Uri-Js. Vendors: npm.

Executive brief

URI.js is a JavaScript library used to parse and manipulate URLs in web applications. When parsing URLs without a scheme (protocol) and with excessive slashes like "///www.example.com", the library incorrectly parses the hostname as null instead of recognizing it as a domain, causing the URL to be treated differently than web browsers would. This can lead to unintended redirects or cross-site request forgery (CSRF) attacks if user input is parsed without proper validation.

Technical details

The vulnerability is a URL parsing inconsistency in URI.js versions prior to 1.19.11. When a URL lacks a scheme and contains excessive leading slashes (e.g., "///www.example.com"), the parser incorrectly sets hostname to null and stores the entire path as "/www.example.com", diverging from browser behavior which treats this as an absolute URL to www.example.com. This discrepancy (CWE-115: Misinterpretation of Input, CWE-601: URL Redirection to Untrusted Site) can be exploited by attackers to craft URLs that bypass validation logic or trigger unintended redirects. The vulnerability requires network-accessible application parsing untrusted URLs and is remotely exploitable without authentication. A patch was released in version 1.19.11 addressing the parsing logic for scheme-relative URLs with excessive slashes.

Affected products

  • medialize uri.js < 1.19.11

Timeline

  • 2022-04-05: disclosed
  • 2022-04-05: patched: Fixed in version 1.19.11

References

Related threats