ids-enterprise@4.21.1 vulnerabilities

Infor Design System (IDS) Enterprise Components for the web

  • latest version

    4.102.0

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    18 hours ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the ids-enterprise package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    ids-enterprise is a framework-independent UI library consisting of CSS and JS that provides product development teams, partners, and customers the tools to create user experiences that are approachable, focused, relevant, perceptive.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS). Script tags inside dropdown options are executed when removing search text using backspace, resulting in execution of JavaScript.

    How to fix Cross-site Scripting (XSS)?

    Upgrade ids-enterprise to version 4.23.0-dev.20191105 or higher.

    <4.23.0-dev.20191105
    • M
    Cross-site Scripting (XSS)

    ids-enterprise is a framework-independent UI library consisting of CSS and JS that provides product development teams, partners, and customers the tools to create user experiences that are approachable, focused, relevant, perceptive.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS). The title and title example value of a modal was found to be unescaped, allowing insertion of JavaScript which is not sanitized.

    How to fix Cross-site Scripting (XSS)?

    Upgrade ids-enterprise to version 4.22.0-beta.0 or higher.

    <4.22.0-beta.0