HIGH8.6
GHSA-xrh7-m5pp-39r6
XSS Attack with Express API
Quick fix
GHSA-xrh7-m5pp-39r6 — eta: upgrade to the fixed version with the command below.
npm install eta@2.0.0Details
### Impact XSS attack - anyone using the Express API is impacted
### Patches The problem has been resolved. Users should upgrade to version 2.0.0.
### Workarounds Don't pass user supplied data directly to `res.renderFile`.
### References _Are there any links users can visit to find out more?_ See https://github.com/eta-dev/eta/releases/tag/v2.0.0
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/eta-dev/eta/security/advisories/GHSA-xrh7-m5pp-39r6[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-23630[ADVISORY]
- https://github.com/eta-dev/eta/commit/5651392462ee0ff19d77c8481081a99e5b9138dd[WEB]
- https://github.com/eta-dev/eta[PACKAGE]
- https://github.com/eta-dev/eta/releases/tag/v2.0.0[WEB]