QID 981834
QID 981834: Nodejs (npm) Security Update for osm-static-maps (GHSA-pxcf-v868-m492)
This affects all versions of package osm-static-maps under 3.9.0. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as an HTML on the page which gives opportunity for XSS or rendered on the server (puppeteer) which also gives opportunity for SSRF and Local File Read.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pxcf-v868-m492 for updates pertaining to this vulnerability.
Vendor References
- GHSA-pxcf-v868-m492 -
github.com/advisories/GHSA-pxcf-v868-m492
CVEs related to QID 981834
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pxcf-v868-m492 | osm-static-maps |
|