Improper Neutralization of Script in Attributes in @dcl/single-sign-on-client
- Severity:
- High
Description
Improper input validation in the init function allows arbitrary javascript to be executed using the javascript: prefix
Recommendation
Update the @dcl/single-sign-on-client package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.1.0
- Patched version(s): 0.1.0
References
Related Issues
- browserify-sign upper bound check issue in `dsaVerify` leads to a signature forgery attack - CVE-2023-46234
- Improper Neutralization of Input During Web Page Generation in Select2 - CVE-2016-10744
- Strapi Improper Rate Limiting vulnerability - @strapi/plugin-users-permissions - CVE-2023-38507
- Strapi Improper Rate Limiting vulnerability - CVE-2023-38507
You might also like:
- Tags:
- npm
- @dcl/single-sign-on-client
Anything's wrong? Let us know Last updated on November 05, 2023


