Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-g7rj-q722-245g: jsreport vulnerable to code injection

jsreport prior to 3.11.3 had a version of vm2 vulnerable to CVE-2023-29017 hard coded in the package.json of the jsreport-core component. An attacker can use this vulnerability to obtain the authority of the jsreport playground server, or construct a malicious webpage/html file and send it to the user to attack the installed jsreport client.

ghsa
#vulnerability#web#js#git#auth

jsreport vulnerable to code injection

Critical severity GitHub Reviewed Published May 8, 2023 to the GitHub Advisory Database • Updated May 9, 2023

Related news

CVE-2023-2583: release extensions 3.11.3 · jsreport/jsreport@afaff38

Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3.