GHSA-588m-9qg5-35pq

Suggest an improvement
Source
https://github.com/advisories/GHSA-588m-9qg5-35pq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-588m-9qg5-35pq/GHSA-588m-9qg5-35pq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-588m-9qg5-35pq
Downstream
Published
2020-09-03T17:19:09Z
Modified
2021-09-28T22:06:18Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Reverse Tabnabbing in quill
Details

Versions of quill prior to 1.3.7 are vulnerable to Reverse Tabnabbing. The package uses target='_blank' in anchor tags, allowing attackers to access window.opener for the original page when opening links. This is commonly used for phishing attacks.

Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

Database specific
{
    "cwe_ids":  [
        "CWE-1022"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:45:03Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / quill

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-588m-9qg5-35pq/GHSA-588m-9qg5-35pq.json"