Cross-Site Scripting in react
Moderate severity
GitHub Reviewed
Published
Sep 4, 2020
to the GitHub Advisory Database
•
Updated May 22, 2023
Package
Affected versions
>= 0.4.0, < 0.4.2
>= 0.5.0, < 0.5.2
Patched versions
0.4.2
0.5.2
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 4, 2020
Last updated
May 22, 2023
Affected versions of
react
are vulnerable to Cross-Site Scripting (XSS). The package fails to properly sanitize input used to create keys. This may allow attackers to execute arbitrary JavaScript if a key is generated from user input.Recommendation
If you are using
react
0.5.x, upgrade to version 0.5.2 or later.If you are using
react
0.4.x, upgrade to version 0.4.2 or later.References