vuetify-2.3.14.tgz: 1 vulnerabilities (highest severity is: 5.4) #1946
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
wontfix
This will not be worked on
Vulnerable Library - vuetify-2.3.14.tgz
Vue Material Component Framework
Library home page: https://registry.npmjs.org/vuetify/-/vuetify-2.3.14.tgz
Path to dependency file: /components/dashboard/node_modules/vuetify/package.json
Path to vulnerable library: /components/dashboard/node_modules/vuetify/package.json
Vulnerabilities
Details
CVE-2022-25873
Vulnerable Library - vuetify-2.3.14.tgz
Vue Material Component Framework
Library home page: https://registry.npmjs.org/vuetify/-/vuetify-2.3.14.tgz
Path to dependency file: /components/dashboard/node_modules/vuetify/package.json
Path to vulnerable library: /components/dashboard/node_modules/vuetify/package.json
Dependency Hierarchy:
Found in base branch: main
Vulnerability Details
The package vuetify from 2.0.0-beta.4 and before 2.6.10 are vulnerable to Cross-site Scripting (XSS) due to improper input sanitization in the 'eventName' function within the VCalendar component.
Publish Date: 2022-09-18
URL: CVE-2022-25873
CVSS 3 Score Details (5.4)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2022-25873
Release Date: 2022-09-18
Fix Resolution: 2.6.10
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: