Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-24709

Опубликовано: 24 фев. 2022
Источник: nvd
CVSS3: 8.8
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

@awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface development. Multiple components in versions before 3.0.367 have been found to not properly neutralize user input and may allow for javascript injection. Users are advised to upgrade to version 3.0.367 or later. There are no known workarounds for this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:amazon:awsui\/components-react:*:*:*:*:*:node.js:*:*
Версия до 3.0.367 (исключая)

EPSS

Процентиль: 60%
0.00391
Низкий

8.8 High

CVSS3

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.8
github
почти 4 года назад

Cross site scripting in @awsui/components-react

EPSS

Процентиль: 60%
0.00391
Низкий

8.8 High

CVSS3

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79