QID 980698
QID 980698: Nodejs (npm) Security Update for rendr (GHSA-v5hp-35hw-cw5x)
Affected versions of `rendr` are vulnerable to cross-site scripting when client side rendering is done inside a `_block`.
Server side rendering is not affected and is properly escaped.
## Recommendation
Update to version 1.1.4 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-v5hp-35hw-cw5x for updates pertaining to this vulnerability.
Vendor References
- GHSA-v5hp-35hw-cw5x -
github.com/advisories/GHSA-v5hp-35hw-cw5x
CVEs related to QID 980698
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v5hp-35hw-cw5x | rendr |
|