CVE-2018-6341
Summary
| CVE | CVE-2018-6341 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-31 22:29:00 UTC |
| Updated | 2019-10-09 23:41:00 UTC |
| Description | React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| React v16.4.2: Server-side vulnerability fix – React Blog | MISC | reactjs.org | Vendor Advisory |
| React Twitter ನಲ್ಲಿ: "We've just released React DOM 16.4.2 to address a security vulnerability (CVE-2018-6341) in ReactDOMServer. https://t.co/NLf5xiiqxX" | MISC | twitter.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 984008 Nodejs (npm) Security Update for react-dom (GHSA-mvjj-gqq2-p4hw)