GHSA-x77j-w7wf-fjmw
Nunjucks autoescape bypass leads to cross site scripting
Quick fix
GHSA-x77j-w7wf-fjmw — nunjucks: upgrade to the fixed version with the command below.
npm install nunjucks@3.2.4Details
### Impact In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash `\` character.
#### Example If the user-controlled parameters were used in the views similar to the following: ``` <script> let testObject = { lang: '{{ lang }}', place: '{{ place }}' }; </script> ```
It is possible to inject XSS payload using the below parameters: ``` https://<application-url>/?lang=jp\&place=};alert(document.domain)// ```
### Patches The issue was patched in version 3.2.4.
### References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1825980
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/mozilla/nunjucks/security/advisories/GHSA-x77j-w7wf-fjmw[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-2142[ADVISORY]
- https://github.com/mozilla/nunjucks/pull/1437[WEB]
- https://github.com/mozilla/nunjucks/commit/ec16d210e7e13f862eccdb0bc9af9f60ff6749d6[WEB]
- https://bugzilla.mozilla.org/show_bug.cgi?id=1825980[WEB]
- https://github.com/mozilla/nunjucks[PACKAGE]
- https://github.com/mozilla/nunjucks/releases/tag/v3.2.4[WEB]