QID 980691
QID 980691: Nodejs (npm) Security Update for c3 (GHSA-gvg7-pp82-cff3)
Affected versions of `c3` are vulnerable to cross-site scripting via improper sanitization of HTML in rendered tooltips.
## Recommendation
Update to 0.4.11 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-gvg7-pp82-cff3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-gvg7-pp82-cff3 -
github.com/advisories/GHSA-gvg7-pp82-cff3
CVEs related to QID 980691
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gvg7-pp82-cff3 | c3 |
|