Описание
urql is a GraphQL client that exposes a set of helpers for several frameworks. The @urql/next package is vulnerable to XSS. To exploit this an attacker would need to ensure that the response returns html tags and that the web-application is using streamed responses (non-RSC). This vulnerability is due to improper escaping of html-like characters in the response-stream. To fix this vulnerability upgrade to version 1.1.1
Ссылки
- Patch
- Vendor Advisory
- Patch
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.1 (исключая)
cpe:2.3:a:nearform:urql:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 69%
0.00618
Низкий
7.2 High
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
EPSS
Процентиль: 69%
0.00618
Низкий
7.2 High
CVSS3
6.1 Medium
CVSS3
Дефекты
CWE-79