QID 980208
QID 980208: Nodejs (npm) Security Update for tempura (GHSA-w4v7-hwx7-9929)
This affects the package tempura before 0.4.0. If the input to the esc function is of type object (i.e an array) it is returned without being escaped/sanitized, leading to a potential Cross-Site Scripting vulnerability.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-w4v7-hwx7-9929 for updates pertaining to this vulnerability.
Vendor References
- GHSA-w4v7-hwx7-9929 -
github.com/advisories/GHSA-w4v7-hwx7-9929
CVEs related to QID 980208
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-w4v7-hwx7-9929 | tempura |
|