elastic-app-search@7.4.0 vulnerabilities

An API client for Elastic App Search

Direct Vulnerabilities

Known vulnerabilities in the elastic-app-search package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cross-site Scripting (XSS)

elastic-app-search is a Python client for the Elastic App Search.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). They contain a cross site scripting (XSS) flaw when displaying document URLs in the Reference UI. If the Reference UI injects a URL into a result, that URL will be rendered by the web browser. If an attacker is able to control the contents of such a field, they could execute arbitrary JavaScript in the victim's web browser.

How to fix Cross-site Scripting (XSS)?

Upgrade elastic-app-search to version 7.7.0 or higher.

[,7.7.0)