QID 982921
QID 982921: Nodejs (npm) Security Update for ansi_up (GHSA-2v5f-23xc-v9qr)
The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2v5f-23xc-v9qr for updates pertaining to this vulnerability.
Vendor References
- GHSA-2v5f-23xc-v9qr -
github.com/advisories/GHSA-2v5f-23xc-v9qr
CVEs related to QID 982921
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2v5f-23xc-v9qr | ansi_up |
|