In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Cross-site Scripting (XSS) vulnerabilities in an interactive lesson.
Start learningUpgrade github.com/open-policy-agent/opa/server
to version 0.9.2 or higher.
github.com/open-policy-agent/opa/server is an open source, general-purpose policy engine that enables unified, context-aware policy enforcement across the entire stack.
Affected versions of this package are vulnerable to Cross-site Scripting (XSS).
The OPA debug page (index.html
) is vulnerable due to the query parameter not being sanitized before being included in the rendered index.html
page.