GHSA-v2jq-9475-r5g8

Suggest an improvement
Source
https://github.com/advisories/GHSA-v2jq-9475-r5g8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-v2jq-9475-r5g8/GHSA-v2jq-9475-r5g8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v2jq-9475-r5g8
Aliases
  • CVE-2016-1000227
Published
2020-09-01T15:29:51Z
Modified
2023-11-08T03:58:07Z
Summary
Cross-Site Scripting in bootstrap-tagsinput
Details

All versions of bootstrap-tagsinput are vulnerable to cross-site scripting when user input is passed into the itemTitle parameter unmodified, as the package fails to properly sanitize or encode user input for that parameter.

Recommendation

This package is not actively maintained, and has not seen an update since 2015.

Because of this, the simplest mitigation is to avoid using the itemTitle parameter. With over 200 open issues and over 100 open pull requests as of 2/2018, it seems unlikely that the author has any intention of maintaining the module. If avoiding the use of itemTitle indefinitely is acceptable, this is a workable solution. If not, the best available mitigation is to use a fork of the module that is actively maintained and provides similar functionality. There are many such forks to choose from available on github..

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:11:37Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / bootstrap-tagsinput

Package

Name
bootstrap-tagsinput
View open source insights on deps.dev
Purl
pkg:npm/bootstrap-tagsinput

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.8.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-v2jq-9475-r5g8/GHSA-v2jq-9475-r5g8.json"