Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g8jj-899q-8x3j

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross-site scripting in json-sanitizer

OWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls another substring adjacent to a SCRIPT element in which the output is embedded as JavaScript, may be able to confuse the HTML parser as to where the SCRIPT element ends, and cause non-script content to be interpreted as JavaScript.

Пакеты

Наименование

com.mikesamuel:json-sanitizer

maven
Затронутые версииВерсия исправления

< 1.2.1

1.2.1

EPSS

Процентиль: 64%
0.00468
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 5 лет назад

OWASP json-sanitizer before 1.2.1 allows XSS. An attacker who controls a substring of the input JSON, and controls another substring adjacent to a SCRIPT element in which the output is embedded as JavaScript, may be able to confuse the HTML parser as to where the SCRIPT element ends, and cause non-script content to be interpreted as JavaScript.

EPSS

Процентиль: 64%
0.00468
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79