From 995f8d957cc5c0fcf5f291c87211325c70797fb2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 22 Jan 2025 20:55:46 +0000 Subject: [PATCH] Publish GHSA-rjjv-87mx-6x3h --- .../2024/11/GHSA-rjjv-87mx-6x3h/GHSA-rjjv-87mx-6x3h.json | 8 ++------ 1 file changed, 2 insertions(+), 6 deletions(-) diff --git a/advisories/github-reviewed/2024/11/GHSA-rjjv-87mx-6x3h/GHSA-rjjv-87mx-6x3h.json b/advisories/github-reviewed/2024/11/GHSA-rjjv-87mx-6x3h/GHSA-rjjv-87mx-6x3h.json index baf97e09b2d..899e693dc84 100644 --- a/advisories/github-reviewed/2024/11/GHSA-rjjv-87mx-6x3h/GHSA-rjjv-87mx-6x3h.json +++ b/advisories/github-reviewed/2024/11/GHSA-rjjv-87mx-6x3h/GHSA-rjjv-87mx-6x3h.json @@ -1,21 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-rjjv-87mx-6x3h", - "modified": "2024-11-25T21:47:02Z", + "modified": "2025-01-22T20:54:21Z", "published": "2024-11-25T15:33:19Z", "aliases": [ "CVE-2024-53261" ], - "summary": "@sveltejs/kit vulnerable to on dev mode 404 page", + "summary": "@sveltejs/kit vulnerable to XSS on dev mode 404 page", "details": "### Summary\n\n\"Unsanitized input from *the request URL* flows into `end`, where it is used to render an HTML page returned to the user. This may result in a Cross-Site Scripting attack (XSS).\"\n\n### Details\n\nSource of potentially tainted data is in `packages/kit/src/exports/vite/dev/index.js`, line 437. This potentially tainted data is passed through a number of steps (which I could detail if you'd like) all the way down to line 91 in `packages/kit/src/exports/vite/utils.js`, which performs an operation that Snyk believes an attacker shouldn't be allowed to manipulate.\n\nAnother source of potentially tainted data (according to Snyk) comes from `‎packages/kit/src/exports/vite/utils.js`, line 30, col 30 (i.e., the `url` property of `req`). This potentially tainted data is passed through a number of steps (which I could detail if you'd like) all the way down line 91 in `packages/kit/src/exports/vite/utils.js`, which performs an operation that Snyk believes an attacker shouldn't be allowed to manipulate.\n\n### PoC\n\nNot provided\n\n### Impact\n\nLittle to none. The Vite development is not exposed to the network by default. And even if someone were able to trick a developer into executing an XSS against themselves, a development database should not have any sensitive data.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:N" - }, - { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P" } ], "affected": [