GHSA-gj3p-j74v-3x57

Suggest an improvement
Source
https://github.com/advisories/GHSA-gj3p-j74v-3x57
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-gj3p-j74v-3x57/GHSA-gj3p-j74v-3x57.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gj3p-j74v-3x57
Aliases
  • CVE-2024-9283
Published
2024-09-27T15:30:35Z
Modified
2024-10-08T19:12:24Z
Severity
  • 3.3 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
ReLaXed Cross-site Scripting vulnerability
Details

A vulnerability classified as problematic has been found in RelaxedJS ReLaXed up to 0.2.2. Affected is an unknown function of the component Pug to PDF Converter. The manipulation leads to cross site scripting. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-10-08T18:56:10Z",
    "nvd_published_at":  "2024-09-27T14:15:05Z",
    "severity":  "LOW"
}
References

Affected packages

npm / relaxedjs

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.2.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-gj3p-j74v-3x57/GHSA-gj3p-j74v-3x57.json"