VDB
Sign up
MEDIUM6.1

GHSA-7f63-h6g3-7cwm

Cross Site Scripting (XSS) in @finastra/ssr-pages

Quick fix

GHSA-7f63-h6g3-7cwm — @finastra/ssr-pages: upgrade to the fixed version with the command below.

npm install @finastra/ssr-pages@0.1.5

Details

A cross site scripting (XSS) issue can occur when providing untrusted input to the `redirect.link` property as an argument to the `build(MessagePageOptions)` function.

### References - https://github.com/Finastra/ssr-pages/pull/2 - https://github.com/Finastra/ssr-pages/pull/2/commits/133606ffaec2edd9918d9fba5771ed21da7876a5 - https://github.com/Finastra/ssr-pages/commit/98abc59e28fec48246be0d59ac144675d6361073

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@finastra/ssr-pages
Introduced in: 0Fixed in: 0.1.5
Fixnpm install @finastra/ssr-pages@0.1.5

References