Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2v5f-23xc-v9qr

Опубликовано: 11 мар. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

ansi_up cross-site scripting vulnerability

The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.

Пакеты

Наименование

ansi_up

npm
Затронутые версииВерсия исправления

< 5.0.0

5.0.0

EPSS

Процентиль: 98%
0.46141
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 5 лет назад

The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.

CVSS3: 6.5
redhat
около 5 лет назад

The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.

CVSS3: 6.1
nvd
почти 5 лет назад

The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.

CVSS3: 6.1
debian
почти 5 лет назад

The npm package ansi_up converts ANSI escape codes into HTML. In ansi_ ...

EPSS

Процентиль: 98%
0.46141
Средний

6.1 Medium

CVSS3

Дефекты

CWE-79