2.20.3
3 years ago
1 months ago
Known vulnerabilities in the @aws-amplify/codegen-ui-react package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
@aws-amplify/codegen-ui-react is an Amplify UI React code generation implementation Affected versions of this package are vulnerable to Eval Injection through the UI component property expressions. An authenticated user who can create or modify components can execute arbitrary JavaScript code during the component rendering and build process by crafting malicious input. How to fix Eval Injection? Upgrade | <2.20.3 |