QID 980507
QID 980507: Nodejs (npm) Security Update for react-native-webview (GHSA-36j3-xxf7-4pqg)
A universal cross-site scripting (UXSS) vulnerability, CVE-2020-6506 (https://crbug.com/1083819), has been identified in the Android WebView system component, which allows cross-origin iframes to execute arbitrary JavaScript in the top-level document. This vulnerability affects React Native apps which use a `react-native-webview` that allows navigation to arbitrary URLs, and when that app runs on systems with an Android WebView version prior to 83.0.4103.106.
## Pending mitigation
Ensure users update their Android WebView system component via the Google Play Store to 83.0.4103.106 or higher to avoid this UXSS. 'react-native-webview' is working on a mitigation but it could take some time.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
- GHSA-36j3-xxf7-4pqg -
github.com/advisories/GHSA-36j3-xxf7-4pqg
CVEs related to QID 980507
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-36j3-xxf7-4pqg | react-native-webview |
|