CVE-2020-8176

Source
https://cve.org/CVERecord?id=CVE-2020-8176
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-8176.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-8176
Aliases
Published
2020-07-02T19:15:12Z
Modified
2026-07-09T00:13:55Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A cross-site scripting vulnerability exists in koa-shopify-auth v3.1.61-v3.1.62 that allows an attacker to inject JS payloads into the shop parameter on the /shopify/auth/enable_cookies endpoint.

References

Affected packages

Git / github.com/shopify/quilt

Affected ranges

Type
GIT
Repo
https://github.com/shopify/quilt
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:shopify:koa-shopify-auth:3.1.61:*:*:*:*:*:*:*",
        "cpe:2.3:a:shopify:koa-shopify-auth:3.1.62:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "3.1.61"
        },
        {
            "last_affected": "3.1.61"
        },
        {
            "introduced": "3.1.62"
        },
        {
            "last_affected": "3.1.62"
        }
    ],
    "source": "CPE_STRING"
}

Affected versions

3.*
3.1.61
3.1.62
@shopify/browser@1.*
@shopify/browser@1.0.0
@shopify/enzyme-utilities@2.*
@shopify/enzyme-utilities@2.1.10
@shopify/enzyme-utilities@2.1.11
@shopify/koa-performance@1.*
@shopify/koa-performance@1.2.4
@shopify/koa-shopify-auth@3.*
@shopify/koa-shopify-auth@3.1.61
@shopify/koa-shopify-auth@3.1.62
@shopify/koa-shopify-graphql-proxy@4.*
@shopify/koa-shopify-graphql-proxy@4.0.0
@shopify/magic-entries-webpack-plugin@0.*
@shopify/magic-entries-webpack-plugin@0.1.0
@shopify/magic-entries-webpack-plugin@0.1.1
@shopify/magic-entries-webpack-plugin@0.1.2
@shopify/performance@1.*
@shopify/performance@1.2.8
@shopify/polyfills@1.*
@shopify/polyfills@1.1.10
@shopify/polyfills@1.1.9
@shopify/react-app-bridge-universal-provider@1.*
@shopify/react-app-bridge-universal-provider@1.0.30
@shopify/react-async@3.*
@shopify/react-async@3.1.17
@shopify/react-cookie@0.*
@shopify/react-cookie@0.0.26
@shopify/react-csrf-universal-provider@1.*
@shopify/react-csrf-universal-provider@1.1.15
@shopify/react-form-state@0.*
@shopify/react-form-state@0.11.22
@shopify/react-form-state@0.11.23
@shopify/react-form@0.*
@shopify/react-form@0.6.2
@shopify/react-google-analytics@3.*
@shopify/react-google-analytics@3.1.11
@shopify/react-google-analytics@3.1.12
@shopify/react-google-analytics@3.1.13
@shopify/react-graphql-universal-provider@3.*
@shopify/react-graphql-universal-provider@3.1.9
@shopify/react-graphql@6.*
@shopify/react-graphql@6.1.9
@shopify/react-hooks@1.*
@shopify/react-hooks@1.10.0
@shopify/react-html@9.*
@shopify/react-html@9.3.10
@shopify/react-hydrate@1.*
@shopify/react-hydrate@1.1.23
@shopify/react-i18n-universal-provider@1.*
@shopify/react-i18n-universal-provider@1.0.55
@shopify/react-i18n@3.*
@shopify/react-i18n@3.0.2
@shopify/react-import-remote@1.*
@shopify/react-import-remote@1.0.41
@shopify/react-performance@1.*
@shopify/react-performance@1.3.4
@shopify/react-router@0.*
@shopify/react-router@0.0.24
@shopify/react-server-webpack-plugin@2.*
@shopify/react-server-webpack-plugin@2.2.34
@shopify/react-server-webpack-plugin@3.*
@shopify/react-server-webpack-plugin@3.0.0
@shopify/react-server-webpack-plugin@3.0.1
@shopify/react-server-webpack-plugin@3.0.2
@shopify/react-server-webpack-plugin@3.0.3
@shopify/react-server@0.*
@shopify/react-server@0.11.0
@shopify/react-server@0.12.0
@shopify/react-server@0.12.1
@shopify/react-tracking-pixel@3.*
@shopify/react-tracking-pixel@3.0.46
@shopify/react-universal-provider@1.*
@shopify/react-universal-provider@1.1.15
@shopify/react-web-worker@1.*
@shopify/react-web-worker@1.2.16
@shopify/react-web-worker@1.2.17
@shopify/react-web-worker@1.2.18
@shopify/web-worker@1.*
@shopify/web-worker@1.3.7
@shopify/web-worker@1.3.8
v1.*
v1.12.1
v1.12.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-8176.json"