CVE-2018-3717: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
(updated )
connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.
References
- github.com/JacksonTian/anywhere/issues/33
- github.com/advisories/GHSA-rch9-xh7r-mqgw
- github.com/senchalabs/connect/commit/6d5dd30075d2bc4ee97afdbbe3d9d98d8d52d74b
- hackerone.com/reports/309394
- hackerone.com/reports/309641
- nvd.nist.gov/vuln/detail/CVE-2018-3717
- www.npmjs.com/advisories/584
- www.npmjs.com/advisories/595
Detect and mitigate CVE-2018-3717 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →