HIGH7.5
GHSA-vp4f-wxgw-7x8x
Improper Neutralization of Script in Attributes in @dcl/single-sign-on-client
Quick fix
GHSA-vp4f-wxgw-7x8x — @dcl/single-sign-on-client: upgrade to the fixed version with the command below.
npm install @dcl/single-sign-on-client@0.1.0Details
### Impact Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix
```ts SSO.init('javascript:alert("javascript successfully injected")') ```
### Patches
This vulnerability was patched on version `0.1.0`
### Workarounds
This vulnerability can be prevented if user input correctly sanitized or there is no user input pass to the `init` function
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/@dcl/single-sign-on-client
Introduced in:
0Fixed in: 0.1.0Fix
npm install @dcl/single-sign-on-client@0.1.0References
- https://github.com/decentraland/single-sign-on-client/security/advisories/GHSA-vp4f-wxgw-7x8x[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-41049[ADVISORY]
- https://github.com/decentraland/single-sign-on-client/pull/2[WEB]
- https://github.com/decentraland/single-sign-on-client/commit/bd20ea9533d0cda30809d929db85b1b76cef855a[WEB]
- https://github.com/decentraland/single-sign-on-client[PACKAGE]