Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h9rv-jmmf-4pgx

Опубликовано: 05 дек. 2019
Источник: github
Github: Прошло ревью
CVSS3: 4.2

Описание

Cross-Site Scripting in serialize-javascript

Versions of serialize-javascript prior to 2.1.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize serialized regular expressions. This vulnerability does not affect Node.js applications.

Recommendation

Upgrade to version 2.1.1 or later.

Пакеты

Наименование

serialize-javascript

npm
Затронутые версииВерсия исправления

< 2.1.1

2.1.1

EPSS

Процентиль: 61%
0.00406
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
почти 6 лет назад

The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affected on Node.js environment since Node.js's implementation of RegExp.prototype.toString() backslash-escapes all forward slashes in regular expressions. If serialized data of regular expression objects are used in an environment other than Node.js, it is affected by this vulnerability.

CVSS3: 4.2
nvd
около 6 лет назад

The serialize-javascript npm package before version 2.1.1 is vulnerable to Cross-site Scripting (XSS). It does not properly mitigate against unsafe characters in serialized regular expressions. This vulnerability is not affected on Node.js environment since Node.js's implementation of RegExp.prototype.toString() backslash-escapes all forward slashes in regular expressions. If serialized data of regular expression objects are used in an environment other than Node.js, it is affected by this vulnerability.

EPSS

Процентиль: 61%
0.00406
Низкий

4.2 Medium

CVSS3

Дефекты

CWE-79