Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-96g7-g7g9-jxw8

Опубликовано: 06 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 9.3

Описание

happy-dom allows for server side code to be executed by a

Impact

Consumers of the NPM package happy-dom

Patches

The security vulnerability has been patched in v15.10.2

Workarounds

No easy workarounds to my knowledge

References

#1585

Пакеты

Наименование

happy-dom

npm
Затронутые версииВерсия исправления

< 15.10.2

15.10.2

EPSS

Процентиль: 70%
0.00637
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-79

Связанные уязвимости

nvd
больше 1 года назад

happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom prior to 15.10.2 may execute code on the host via a script tag. This would execute code in the user context of happy-dom. Users are advised to upgrade to version 15.10.2. There are no known workarounds for this vulnerability.

EPSS

Процентиль: 70%
0.00637
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-79