Description
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.
Remediation
References
https://snyk.io/vuln/SNYK-JS-NODEREDDASHBOARD-471939
Related Vulnerabilities
CVE-2021-39149 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2022-0437 Vulnerability in npm package karma
CVE-2020-25689 Vulnerability in maven package org.wildfly.core:wildfly-protocol
CVE-2023-30524 Vulnerability in maven package org.jenkins-ci.plugins:reportportal
CVE-2023-48967 Vulnerability in maven package org.noear:solon.serialization.fury