Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2217

Опубликовано: 27 июн. 2022
Источник: redhat
CVSS3: 6.1

Описание

Cross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/parse-url prior to 7.0.0.

A cross-site-scripting (XSS) flaw was found in the parse-url package of npm. This issue could allow an attacker to use escape characters to run malicious JavaScript code on a webpage that was generated by the affected package. The highest impact is to integrity and confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apicurio Registry 2parse-urlNot affected
Red Hat Decision Manager 7parse-urlOut of support scope
Red Hat Integration Camel K 1parse-urlNot affected
Red Hat Integration Data Virtualisation Operatorparse-urlNot affected
Red Hat Integration Service Registryparse-urlNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-consoleWill not fix
Red Hat OpenShift Dev Spacesdevspaces/dashboard-rhel8Not affected
Red Hat OpenShift distributed tracing 2rhosdt/jaeger-all-in-one-rhel8Affected
Red Hat OpenShift distributed tracing 2rhosdt/jaeger-query-rhel8Affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argocd-rhel8Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
больше 3 лет назад

Cross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/parse-url prior to 7.0.0.

CVSS3: 6.1
github
больше 3 лет назад

Cross site scripting in parse-url

6.1 Medium

CVSS3