Description
URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
Remediation
References
https://advisory.checkmarx.net/advisory/CX-2021-4305
https://github.com/medialize/URI.js/commit/a1ad8bcbc39a4d136d7e252e76e957f3ece70839
https://github.com/medialize/URI.js/releases/tag/v1.19.6
Related Vulnerabilities
CVE-2013-4152 Vulnerability in maven package org.springframework:spring-web
CVE-2020-28847 Vulnerability in npm package valine
CVE-2018-17421 Vulnerability in maven package com.zrlog:zrlog
CVE-2022-31127 Vulnerability in npm package next-auth
CVE-2021-3827 Vulnerability in maven package org.keycloak:keycloak-server-spi-private