MEDIUM4.8
GHSA-vc68-6x72-w22f
Raneto vulnerable to Cross-site Scripting
Quick fix
GHSA-vc68-6x72-w22f — raneto: upgrade to the fixed version with the command below.
npm install raneto@0.17.1Details
Renato v0.17.0 was discovered to contain a cross-site scripting (XSS) vulnerability. This issue is fixed in version 0.17.1.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-35144[ADVISORY]
- https://github.com/ryanlelek/Raneto/pull/370[WEB]
- https://cwe.mitre.org/data/definitions/79.html[WEB]
- https://gainsec.com/2022/08/04/cve-2022-35142-cve-2022-35143-cve-2022-35144[WEB]
- https://github.com/ryanlelek/Raneto[PACKAGE]
- https://github.com/ryanlelek/Raneto/releases/tag/0.17.1[WEB]
- http://raneto.com[WEB]