QID 983990
QID 983990: Nodejs (npm) Security Update for tianma-static (GHSA-jhgp-hvj6-x2p2)
All versions of `tianma-static` are vulnerable to stored cross-site scripting (XSS). The vulnerability is exploitable if a user can control the name of a file that is served by `tianma-static` ## Recommendation As no fix is available for this vulnerability at this time it is our recommendation to use another static file server.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jhgp-hvj6-x2p2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-jhgp-hvj6-x2p2 -
github.com/advisories/GHSA-jhgp-hvj6-x2p2
CVEs related to QID 983990
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jhgp-hvj6-x2p2 | tianma-static |
|