CVE-2023-1496

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in go/github.com/imgproxy/imgproxy/v3

Identifiers

GHSA-ch9g-x9j7-rcgp, CVE-2023-1496

Package Slug

go/github.com/imgproxy/imgproxy/v3

Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description

Cross-site Scripting (XSS) - Reflected in GitHub repository imgproxy/imgproxy prior to 3.14.0.

Affected Versions

All versions before 3.14.0

Solution

Upgrade to version 3.14.0 or above.

Last Modified

2023-03-22

source