Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-2142

Опубликовано: 26 нояб. 2024
Источник: debian

Описание

In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-nunjucksfixed3.2.4+~cs4.2.7-1package
node-nunjucksno-dsabookwormpackage

Примечания

  • https://bugzilla.mozilla.org/show_bug.cgi?id=1825980

  • https://github.com/mozilla/nunjucks/security/advisories/GHSA-x77j-w7wf-fjmw

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 1 года назад

In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.

CVSS3: 5.4
redhat
около 1 года назад

In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.

CVSS3: 6.1
nvd
около 1 года назад

In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.

CVSS3: 6.1
github
почти 3 года назад

Nunjucks autoescape bypass leads to cross site scripting