QID 984153
QID 984153: Python (pip) Security Update for python-cjson (GHSA-95jp-77w6-qj52)
Python-cjson 1.0.5 does not properly handle a ['/'] argument to cjson.encode, which makes it easier for remote attackers to conduct certain cross-site scripting (XSS) attacks involving Firefox and the end tag of a SCRIPT element.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-95jp-77w6-qj52 for updates pertaining to this vulnerability.
Vendor References
- GHSA-95jp-77w6-qj52 -
github.com/advisories/GHSA-95jp-77w6-qj52
CVEs related to QID 984153
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-95jp-77w6-qj52 | python-cjson |
|