com.vaadin:vaadin-spreadsheet-flow@24.8.8

  • latest version

    25.2.6

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    16 days ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the com.vaadin:vaadin-spreadsheet-flow package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the ContextMenuManager and Action classed, when handling Action captions. An attacker can cause scripts to be executed by injecting them into captions.

    Note: As of version 23, the Action class is only used by the Spreadsheet component.

    How to fix Cross-site Scripting (XSS)?

    Upgrade com.vaadin:vaadin-spreadsheet-flow to version 23.6.6, 24.8.14, 24.9.6 or higher.

    [23.1.0,23.6.6)[24.0.0,24.8.14)[24.9.0,24.9.6)