GHSA-6m4r-cgm3-6q7q

Suggest an improvement
Source
https://github.com/advisories/GHSA-6m4r-cgm3-6q7q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/09/GHSA-6m4r-cgm3-6q7q/GHSA-6m4r-cgm3-6q7q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6m4r-cgm3-6q7q
Aliases
Published
2019-09-23T18:32:54Z
Modified
2023-11-08T04:01:13Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Cross-Site Scripting in status-board
Details

All versions of status-board are vulnerable to Cross-Site Scripting. The renderJsDashboard() function concatenates the safeDashboard variable to the HTTP response message with insufficient sanitization. If this variable is controlled by user input it may allow attackers to execute arbitrary JavaScript in a victim's browser.

Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-09-19T15:15:56Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / status-board

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.1.82

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/09/GHSA-6m4r-cgm3-6q7q/GHSA-6m4r-cgm3-6q7q.json"