CVE-2021-27516

Related Vulnerabilities: CVE-2021-27516  

URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.

Description

The MITRE CVE dictionary describes this issue as:

URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.

Additional Information

  • Bugzilla 1934470: CVE-2021-27516 yarnpkg-urijs: mishandling certain uses of backslash may lead to confidentiality compromise
  • CWE-20: Improper Input Validation
  • FAQ: Frequently asked questions about CVE-2021-27516