Input validation error in URI.js - CVE-2022-24723

 

Input validation error in URI.js - CVE-2022-24723

Published: November 28, 2022


Vulnerability identifier: #VU69644
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-24723
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify application behavior.

The vulnerability exists due to insufficient validation of user-supplied input when handling whitespace characters  in URL. A remote attacker can pass specially crafted input to the application and modify application behavior.


Affected software

URI.js
Fuse
Red Hat Advanced Cluster Management for Kubernetes
Robotic Process Automation for Cloud Pak

How to mitigate CVE-2022-24723

Install updates from vendor's website.

URI.js - update to 1.19.9
Fuse - update to 7.11.1
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.3.10, 2.4.4
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.1, 23.0.1

External References

Related Security Bulletins