Vulnerabilities/

Cross-Site Scripting (XSS) in Verdaccio

Severity:
Medium

Description

What kind of vulnerability is it? Who is impacted?

Cross-Site Scripting XSS, malicious packages with content Javascript that might be executed in the User Interface stealing user credentials.

Recommendation

Update the verdaccio package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
verdaccio
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing