MEDIUM6.1
GHSA-3q6f-8grx-pr4v
Cross-site scripting in jspdf
Quick fix
GHSA-3q6f-8grx-pr4v — jspdf: upgrade to the fixed version with the command below.
npm install jspdf@2.0.0Details
It's possible to use nested script tags in order to bypass the filtering regex.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-7691[ADVISORY]
- https://github.com/MrRio/jsPDF/issues/2971[WEB]
- https://github.com/MrRio/jsPDF/commit/d0323215b1a1cd1c35bf2b213274ae1e4797715d[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-575255[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-575253[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBMRRIO-575254[WEB]
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-575252[WEB]
- https://snyk.io/vuln/SNYK-JS-JSPDF-568273[WEB]