Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2v5f-23xc-v9qr

Опубликовано: 11 мар. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

ansi_up cross-site scripting vulnerability

The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.

Пакеты

Наименование

ansi_up

npm
Затронутые версииВерсия исправления

< 5.0.0

5.0.0

EPSS

Процентиль: 94%
0.08
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.

CVSS3: 6.5
redhat
больше 5 лет назад

The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.

CVSS3: 6.1
nvd
больше 5 лет назад

The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.

CVSS3: 6.1
debian
больше 5 лет назад

The npm package ansi_up converts ANSI escape codes into HTML. In ansi_ ...

EPSS

Процентиль: 94%
0.08
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79