VDB
Sign up
MEDIUM6.1

GHSA-78j5-gcmf-vqc8

Cross-Site Scripting (XSS) in Verdaccio

Quick fix

GHSA-78j5-gcmf-vqc8 — verdaccio: upgrade to the fixed version with the command below.

npm install verdaccio@3.12.0

Details

### Impact What kind of vulnerability is it? Who is impacted?

Cross-Site Scripting XSS, malicious packages with content Javascript that might be executed in the User Interface stealing user credentials.

### Patches Has the problem been patched? What versions should users upgrade to?

Users that still using `v3` must upgrade to **>3.12.0** or those have no problem to migrate to a major version **>=4.0.0** also fix the issue.

### Workarounds Is there a way for users to fix or remediate the vulnerability without upgrading?

No, the users must update.

### References Are there any links users can visit to find out more?

https://www.npmjs.com/advisories/832 https://www.npmjs.com/advisories/833

The issue was reported by the NPMJS Security Team

### For more information If you have any questions or comments about this advisory: * Read the Security Policy to find the ways to be in contact with us.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/verdaccio
Introduced in: 0Fixed in: 3.12.0
Fixnpm install verdaccio@3.12.0

References