MEDIUM6.1
GHSA-vrv9-3x3w-ffxw
node-red-dashboard vulnerable to Cross-site Scripting
Quick fix
GHSA-vrv9-3x3w-ffxw — node-red-dashboard: upgrade to the fixed version with the command below.
npm install node-red-dashboard@3.2.0Details
node-red-dashboard contains a cross-site scripting vulnerability. This issue affects some unknown processing of the file `components/ui-component/ui-component-ctrl.js` of the component ui_text Format Handler. The attack may be initiated remotely. The issue is patched in version 3.2.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-3783[ADVISORY]
- https://github.com/node-red/node-red-dashboard/issues/772[WEB]
- https://github.com/node-red/node-red-dashboard/commit/9305d1a82f19b235dfad24a7d1dd4ed244db7743[WEB]
- https://github.com/node-red/node-red-dashboard[PACKAGE]
- https://vuldb.com/?id.212555[WEB]