CVE-2018-6341
Dashboard / Vulnerabilities / CVE-2018-6341
Summary:
Details: React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.
References: https://reactjs.org/blog/2018/08/01/react-v-16-4-2.html, https://twitter.com/reactjs/status/1024745321987887104
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 8765d608935a81ba5019f6cde6dce3367d392f0c
Affected versions
v16.4.1
v16.4.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
