Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c3m8-x3cg-qm2c

Опубликовано: 03 сент. 2020
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Configuration Override in helmet-csp

Versions of helmet-csp before to 2.9.1 are vulnerable to a Configuration Override affecting the application's Content Security Policy (CSP). The package's browser sniffing for Firefox deletes the default-src CSP policy, which is the fallback policy. This allows an attacker to remove an application's default CSP, possibly rendering the application vulnerable to Cross-Site Scripting.

Recommendation

Upgrade to version 2.9.1 or later. Setting the browserSniff configuration to false in vulnerable versions also mitigates the issue.

Пакеты

Наименование

helmet-csp

npm
Затронутые версииВерсия исправления

>= 1.2.2, < 2.9.1

2.9.1

6.5 Medium

CVSS3

6.5 Medium

CVSS3