org.webjars.npm:dompurify@3.1.1 vulnerabilities
-
latest version
3.1.7
-
latest non vulnerable version
-
first published
6 years ago
-
latest version published
a month ago
-
licenses detected
- (Apache-2.0 OR MPL-2.0)[2.2.3,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the org.webjars.npm:dompurify package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
org.webjars.npm:dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Cross-site Scripting (XSS) through the improper sanitization of nested HTML elements in the How to fix Cross-site Scripting (XSS)? Upgrade |
[,2.5.0)
[3.0.0,3.1.3)
|
org.webjars.npm:dompurify is a DOM-only XSS sanitizer for HTML, MathML and SVG. Affected versions of this package are vulnerable to Prototype Pollution due to improper user input sanitization through the depth-checking mechanism, an attacker can exploit this vulnerability by using special nesting techniques to create a malicious HTML file. How to fix Prototype Pollution? Upgrade |
[,2.5.6)
[3.0.0,3.1.4)
|