CVE-2021-27516

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/02/2021
Last modified:
29/11/2022

Description

URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:uri.js_project:uri.js:*:*:*:*:*:*:*:* 1.19.6 (excluding)