QID 982688
QID 982688: Nodejs (npm) Security Update for xmlhttprequest-ssl (GHSA-h4j5-c7cj-74xg)
This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h4j5-c7cj-74xg for updates pertaining to this vulnerability.
Vendor References
- GHSA-h4j5-c7cj-74xg -
github.com/advisories/GHSA-h4j5-c7cj-74xg
CVEs related to QID 982688
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h4j5-c7cj-74xg | xmlhttprequest |
|
|
| GHSA-h4j5-c7cj-74xg | xmlhttprequest-ssl |
|