VDB
Sign up
MEDIUM

GHSA-mj87-8xf8-fp4w

Cross-Site Scripting in yui

Quick fix

GHSA-mj87-8xf8-fp4w — yui: upgrade to the fixed version with the command below.

npm install yui@3.10.3

Details

Affected versions of `yui` are vulnerable to cross-site scripting in the `uploader.swf` and `io.swf` utilities, via script injection in the url.

## Recommendation

YUI has published their recommendation to fix this issue. Their recommendation is to: - Delete self-hosted copies of these files if you are not using them - Use the Yahoo! CDN hosted files - Use the patched files provided on the YUI Library [here](https://yuilibrary.com/support/20130515-vulnerability/#resolution).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/yui
Introduced in: 0Fixed in: 3.10.3
Fixnpm install yui@3.10.3

References