Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g3ch-rx76-35fx

Опубликовано: 23 июл. 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.2

Описание

vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)

A vulnerability has been discovered in vue-template-compiler, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of some properties such as Object.prototype.staticClass or Object.prototype.staticStyle to execute arbitrary JavaScript code. Vue 2 has reached End-of-Life. This vulnerability has been patched in Vue 3.

Пакеты

Наименование

vue-template-compiler

npm
Затронутые версииВерсия исправления

>= 2.0.0

Отсутствует

EPSS

Процентиль: 35%
0.00142
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
nvd
больше 1 года назад

A vulnerability has been discovered in Vue, that allows an attacker to perform XSS via prototype pollution. The attacker could change the prototype chain of some properties such as `Object.prototype.staticClass` or `Object.prototype.staticStyle` to execute arbitrary JavaScript code.

EPSS

Процентиль: 35%
0.00142
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-79