QID 980863
QID 980863: Nodejs (npm) Security Update for serve-index (GHSA-v633-x5vv-hqwc)
Versions 1.6.2 and earlier of `serve-index` are affected by a cross-site scripting vulnerability. Because file and directory names are not escaped in the module's HTML output, a remote attacker that can influence file or directory names can launch a persistent cross-site scripting attack on the application.
## Recommendation
Update to version 1.6.3 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-v633-x5vv-hqwc for updates pertaining to this vulnerability.
Vendor References
- GHSA-v633-x5vv-hqwc -
github.com/advisories/GHSA-v633-x5vv-hqwc
CVEs related to QID 980863
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-v633-x5vv-hqwc | serve-index |
|