QID 980686

QID 980686: Nodejs (npm) Security Update for yui (GHSA-mj87-8xf8-fp4w)

Affected versions of `yui` are vulnerable to cross-site scripting in the `uploader.swf` and `io.swf` utilities, via script injection in the url.



## Recommendation

YUI has published their recommendation to fix this issue.
Their recommendation is to:
- Delete self-hosted copies of these files if you are not using them
- Use the Yahoo! CDN hosted files
- Use the patched files provided on the YUI Library [here](https://yuilibrary.com/support/20130515-vulnerability/#resolution).

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-mj87-8xf8-fp4w for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980686

    Software Advisories
    Advisory ID Software Component Link
    GHSA-mj87-8xf8-fp4w yui URL Logo github.com/advisories/GHSA-mj87-8xf8-fp4w