Intel

AIKIDO-2024-10532

shopify_app is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)CVE-2024-54133 Published Dec 13, 2024

23

Low Risk

This Affects:

rubyshopify_app
21.4.1 - 22.5.0
Fixed in 22.5.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) due to improper handling of Content-Security-Policy (CSP) headers. Applications that dynamically generate CSP headers using untrusted user input are at risk, as attackers can craft inputs that inject malicious directives into the CSP. This vulnerability can effectively bypass the CSP, undermining its protections against XSS and other web-based attacks, potentially compromising the security of the application and its users. While a fix for this issue was introduced in Rails core, the affected package implemented its own mitigation measures to address the risk.

Who does this affect?

You are affected if you are using a vulnerable version of the package.

Background info

shopify_app is vulnerable to Cross-site Scripting (XSS) in versions 21.4.1 - 22.5.0.

How to fix this

Upgrade the shopify_app library to the patch version.