Intel

AIKIDO-2024-10334

astro is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2024-47885 Published Oct 14, 2024

59

Medium Risk

This Affects:

jsastro
3.2.0 - 4.16.0
Fixed in 4.16.1
Are you affected? Scan for Free

TL;DR

AAffected versions of the package are vulnerable to Cross-site Scripting (XSS). If the application uses name="scripts", it will shadow the built-in document.scripts, potentially allowing an attacker to inject malicious scripts into the application.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

astro is vulnerable to Cross-site Scripting (XSS) in versions 3.2.0 - 4.16.0.

How to fix this

Upgrade the astro library to the patch version.