VDB
Sign up
HIGH7.5

GHSA-w387-5qqw-7g8m

Content-Security-Policy header generation in middleware could be compromised by malicious injections

Quick fix

GHSA-w387-5qqw-7g8m — @kindspells/astro-shield: upgrade to the fixed version with the command below.

npm install @kindspells/astro-shield@1.3.0

Details

### Impact

When the following conditions are met: - Automated CSP headers generation for SSR content is enabled - The web application serves content that can be partially controlled by external users

Then it is possible that the CSP headers generation feature might be "allow-listing" malicious injected resources like inlined JS, or references to external malicious scripts.

### Patches Available in version 1.3.0 .

### Workarounds - Do not enable CSP headers generation. - Use it only for dynamically generated content that cannot be controlled by external users in any way.

### References _Are there any links users can visit to find out more?_

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@kindspells/astro-shield
Introduced in: 1.2.0Fixed in: 1.3.0
Fixnpm install @kindspells/astro-shield@1.3.0

References