Описание
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
node-mermaid | fixed | 8.14.0+~cs11.4.14-1 | package | |
node-mermaid | fixed | 8.7.0+ds+~cs27.17.17-3+deb11u1 | bullseye | package |
Примечания
https://github.com/braintree/sanitize-url/pull/40
src:node-mermaid provides embedded @braintree/sanitize-url
Связанные уязвимости
CVSS3: 5.4
ubuntu
больше 3 лет назад
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
CVSS3: 5.4
redhat
больше 3 лет назад
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
CVSS3: 5.4
nvd
больше 3 лет назад
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.