Описание
sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| node-mermaid | removed | package | ||
| node-mermaid | no-dsa | bullseye | package |
Примечания
https://github.com/braintree/sanitize-url/commit/d4bdc89f1743fe3cdb7c3f24b06e4c875f349b0c
Связанные уязвимости
CVSS3: 6.1
ubuntu
почти 3 года назад
sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
CVSS3: 6.1
redhat
почти 3 года назад
sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
CVSS3: 6.1
nvd
почти 3 года назад
sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
CVSS3: 6.1
github
почти 3 года назад
@braintree/sanitize-url Cross-site Scripting vulnerability