VDB
Sign up
CRITICAL10.0

GHSA-g7rj-q722-245g

jsreport vulnerable to code injection

Quick fix

GHSA-g7rj-q722-245g — jsreport: upgrade to the fixed version with the command below.

npm install jsreport@3.11.3

Details

jsreport prior to 3.11.3 had a version of vm2 vulnerable to CVE-2023-29017 hard coded in the package.json of the jsreport-core component. An attacker can use this vulnerability to obtain the authority of the jsreport playground server, or construct a malicious webpage/html file and send it to the user to attack the installed jsreport client.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jsreport
Introduced in: 0Fixed in: 3.11.3
Fixnpm install jsreport@3.11.3

References