Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2603 | @dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix. This vulnerability has been patched on version `0.1.0`. Users are advised to upgrade. Users unable to upgrade should limit untrusted user input to the `init` function. |
Github GHSA |
GHSA-vp4f-wxgw-7x8x | Improper Neutralization of Script in Attributes in @dcl/single-sign-on-client |
Tue, 01 Oct 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-01T13:08:08.826Z
Reserved: 2023-08-22T16:57:23.933Z
Link: CVE-2023-41049
Updated: 2024-08-02T18:46:11.758Z
Status : Modified
Published: 2023-09-01T20:15:07.873
Modified: 2024-11-21T08:20:27.487
Link: CVE-2023-41049
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA