Junglewise Threat Intelligence

CVE-2022-1243: medialize urijs incorrect protocol extraction via whitespace characters

CVE-2022-1243 · Severity: low · CVSS 3 · Published 2022-04-06

Technologies: urijs (npm). Vendors: npm.

Executive brief

A vulnerability in the urijs library, a tool used by developers to process and validate web addresses (URLs), could allow attackers to bypass security filters. By inserting hidden characters like tabs or new lines into a link, an attacker can trick an application into treating a dangerous script as a safe web link. This can lead to Cross-Site Scripting (XSS) attacks, where malicious code is executed in a user's browser, potentially leading to account takeover or data theft.

Technical details

The urijs library (npm package) prior to version 1.19.11 fails to properly sanitize or account for whitespace characters such as \r, \n, and \t during URL parsing. An attacker can craft a URL (e.g., 'ja\r\nvascript:alert(1)') that the library fails to identify as having a 'javascript:' protocol. If an application relies on urijs to validate and block malicious protocols before rendering links in HTML, this flaw allows for a bypass. This leads to Cross-Site Scripting (XSS) when the malformed URL is subsequently executed by a browser that ignores those characters. The issue is fixed in version 1.19.11.

Affected products

  • medialize urijs < 1.19.11

Timeline

  • 2022-04-05: advisory: NVD published CVE-2022-1243
  • 2022-04-06: disclosed: GHSA-3vjf-82ff-p4r3 published
  • 2022-04-07: patched: Fix committed to medialize/URI.js repository

References

Related threats