-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Cross-site scripting (XSS) vulnerability CVE-2024-37063 #1599
Comments
Solved with PR #1626 |
@fabclmnt can you please explain how it fixes the problem mentioned in https://hiddenlayer.com/sai-security-advisory/ydata-june2024 ? This PR #1604 seems like a fix. For reference from the article:
|
@jjshinobi @fabclmnt I can confirm this vulnerability is still present in version 4.9.0 since the PR #1626 was merged Can this issue be reopened? |
Current Behaviour
GHSA-2r57-2mrh-ggjv
A cross-site scripting (XSS) vulnerability in versions 3.7.0 or newer of Ydata's ydata-profiling open-source library allows for payloads to be run when a maliocusly crafted report is viewed in the browser.
References
Expected Behaviour
Secured
Data Description
N/A
Code that reproduces the bug
No response
pandas-profiling version
Dependencies
OS
All OSes
Checklist
The text was updated successfully, but these errors were encountered: