QID 983758
QID 983758: Nodejs (npm) Security Update for @risingstack/protect (GHSA-vpch-rxw3-fgx8)
All versions of `@risingstack/protect` are vulnerable to Cross-Site Scripting. The `isXss()` XSS validator has several bypasses that may allow attackers to execute arbitrary JavaScript in a victim's browser. ## Recommendation No fix is currently available. Consider using an alternative package. The package is not actively maintained and will not be patched.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vpch-rxw3-fgx8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-vpch-rxw3-fgx8 -
github.com/advisories/GHSA-vpch-rxw3-fgx8
CVEs related to QID 983758
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vpch-rxw3-fgx8 | @risingstack/protect |
|