Description
More methods than expected can be called on reflex instances. Being able to call some of them has security implications.
Recommendation
Update the stimulus_reflex package to the latest compatible version. Followings are version details:
Affected version(s): **>= 3.5.0-pre0, < 3.5.0-rc4 < 3.4.2** Patched version(s): **3.5.0-rc4 3.4.2**
References
Related Issues
- TurboBoost Commands vulnerable to arbitrary method invocation - CVE-2024-28181
- jquery-validation Regular Expression Denial of Service due to arbitrary input to url2 method - CVE-2022-31147
- VvvebJs Arbitrary File Upload vulnerability - CVE-2024-29272
- Saltcorn Server allows logged-in users to delete arbitrary files because of a path traversal vulnerability - CVE-2024-47818
You might also like:
- Tags:
- npm
- stimulus_reflex
Anything's wrong? Let us know Last updated on September 25, 2024


