QID 981424
QID 981424: Nodejs (npm) Security Update for plotly.js (GHSA-2fqv-h3r5-m4vf)
Affected versions of `plotly.js` are vulnerable to cross-site scripting if an attacker can convince a user to visit a malicious plot on a site using this package.
## Recommendation
Update to 1.16.0 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2fqv-h3r5-m4vf for updates pertaining to this vulnerability.
Vendor References
- GHSA-2fqv-h3r5-m4vf -
github.com/advisories/GHSA-2fqv-h3r5-m4vf
CVEs related to QID 981424
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2fqv-h3r5-m4vf | plotly.js |
|