Vulnerabilities/

@dependencytrack/frontend vulnerable to Persistent Cross-Site-Scripting via Vulnerability Details

Severity:
Medium

Description

Due to the common practice of providing vulnerability details in markdown format, the Dependency-Track frontend renders them using the JavaScript library Showdown. Showdown does not have any XSS countermeasures built in), and versions before 4.6.1 of the Dependency-Track frontend did not encode or sanitize Showdown’s output.

Recommendation

Update the @dependencytrack/frontend package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@dependencytrack/frontend
Anything's wrong? Let us know Last updated on January 30, 2023

This issue is available in SmartScanner Professional

See Pricing