GHSA-g53w-52xc-2j85

Suggest an improvement
Source
https://github.com/advisories/GHSA-g53w-52xc-2j85
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-g53w-52xc-2j85/GHSA-g53w-52xc-2j85.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g53w-52xc-2j85
Aliases
  • CVE-2013-7035
Published
2020-09-04T16:52:57Z
Modified
2023-11-08T03:57:27Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Cross-Site Scripting in react
Details

Affected versions of react are vulnerable to Cross-Site Scripting (XSS). The package fails to properly sanitize input used to create keys. This may allow attackers to execute arbitrary JavaScript if a key is generated from user input.

Recommendation

If you are using react 0.5.x, upgrade to version 0.5.2 or later. If you are using react 0.4.x, upgrade to version 0.4.2 or later.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-08-31T18:58:42Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

npm / react

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.4.0
Fixed
0.4.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-g53w-52xc-2j85/GHSA-g53w-52xc-2j85.json"

npm / react

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.5.0
Fixed
0.5.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-g53w-52xc-2j85/GHSA-g53w-52xc-2j85.json"