QID 983870
QID 983870: Nodejs (npm) Security Update for igniteui (GHSA-2r5h-gh4x-8hp9)
Affected versions of `igniteui` download Javascript and CSS resources over an unencrypted HTTP connection. An attacker with a privileged network position can intercept and view or modify any content sent or recieved over an unencrypted HTTP connection. ## Recommendation The `igniteui` package has been deprecated by the package author and now exists under [`ignite-ui`](https://preview.npmjs.com/package/ignite-ui), which should be used in place of this package.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2r5h-gh4x-8hp9 for updates pertaining to this vulnerability.
Vendor References
- GHSA-2r5h-gh4x-8hp9 -
github.com/advisories/GHSA-2r5h-gh4x-8hp9
CVEs related to QID 983870
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2r5h-gh4x-8hp9 | igniteui |
|