ethyca-fides@2.84.1a0

Open-source ecosystem for data privacy as code.

  • latest version

    2.86.2

  • latest non vulnerable version

  • first published

    3 years ago

  • latest version published

    2 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the ethyca-fides package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Cross-site Scripting (XSS)

    ethyca-fides is an Open-source ecosystem for data privacy as code.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the fides.js script's override mechanism for the banner description field when HTML-formatted descriptions are enabled. An attacker can execute arbitrary JavaScript in the context of the embedding site's origin by supplying a crafted value through a URL parameter, JavaScript global, or cookie, leading to persistent script execution across all subdomains until cookies are cleared. This is only exploitable if the HTML description feature is enabled (the FIDES_PRIVACY_CENTER__ALLOW_HTML_DESCRIPTION environment variable is set to true).

    How to fix Cross-site Scripting (XSS)?

    Upgrade ethyca-fides to version 2.84.5rc0 or higher.

    [2.33.0,2.84.5rc0)