Skip to content

Cross Site Scripting (XSS) in @finastra/ssr-pages

High
bcldvd published GHSA-7f63-h6g3-7cwm Mar 1, 2022

Package

npm @finastra/ssr-pages (npm)

Affected versions

< 0.1.5

Patched versions

0.1.5

Description

A cross site scripting (XSS) issue can occur when providing untrusted input to the redirect.link property as an argument to the build(MessagePageOptions) function.

References

Severity

High

CVE ID

CVE-2022-24717

Weaknesses

Credits