Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-32468

Опубликовано: 25 нояб. 2024
Источник: nvd
CVSS3: 5.4
EPSS Низкий

Описание

Deno is a runtime for JavaScript and TypeScript written in rust. Several cross-site scripting vulnerabilities existed in the deno_doc crate which lead to Self-XSS with deno doc --html. 1.) XSS in generated search_index.js, deno_doc outputs a JavaScript file for searching. However, the generated file used innerHTML on unsanitzed HTML input. 2.) XSS via property, method and enum names, deno_doc did not sanitize property names, method names and enum names. The first XSS most likely didn't have an impact since deno doc --html is expected to be used locally with own packages.

EPSS

Процентиль: 25%
0.00088
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
github
около 1 года назад

deno_doc's HTML generator vulnerable to Cross-site Scripting

EPSS

Процентиль: 25%
0.00088
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79