原始 OSV JSON{
"id": "GHSA-8fw4-xh83-3j6q",
"aliases": [],
"details": "Versions of `diagram-js` prior to 3.3.1 (for 3.x) and 2.6.2 (for 2.x) are vulnerable to Cross-Site Scripting. The package fails to escape output of user-controlled input in `search-pad`, allowing attackers to execute arbitrary JavaScript.\n\n\n## Recommendation\n\nIf you are using diagram-js 3.x, upgrade to version 3.3.1.\nIf you are using diagram-js 2.x, upgrade to version 2.6.2.",
"summary": "Cross-Site Scripting in diagram-js",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "2.6.2"
}
]
}
],
"package": {
"name": "diagram-js",
"ecosystem": "npm"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.0.0"
},
{
"fixed": "3.3.1"
}
]
}
],
"package": {
"name": "diagram-js",
"ecosystem": "npm"
}
}
],
"modified": "2021-09-28T16:58:42Z",
"severity": [],
"published": "2020-09-11T21:18:05Z",
"references": [
{
"url": "https://github.com/bpmn-io/diagram-js/commit/2565c40449379284a55163f290ec812db34244d1",
"type": "WEB"
},
{
"url": "https://github.com/bpmn-io/diagram-js/commit/777fa06d70036daa9d02f3be6d0732cf4ccd8d6d",
"type": "WEB"
},
{
"url": "https://bpmn.io/blog/posts/2019-html-injection-vulnerabilities-fixed.html",
"type": "WEB"
},
{
"url": "https://github.com/bpmn-io/diagram-js",
"type": "PACKAGE"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": true,
"nvd_published_at": null,
"github_reviewed_at": "2020-08-31T18:42:58Z"
}
}