Description
verdaccio before 3.12.0 allows XSS.
Remediation
References
https://github.com/verdaccio/verdaccio/security/advisories/GHSA-78j5-gcmf-vqc8
Related Vulnerabilities
CVE-2018-3721 Vulnerability in maven package org.webjars.npm:lodash.merge
CVE-2021-23412 Vulnerability in npm package gitlogplus
CVE-2023-36665 Vulnerability in maven package org.webjars.npm:protobufjs
CVE-2020-7709 Vulnerability in maven package org.webjars.npm:json-pointer
CVE-2020-6423 Vulnerability in maven package org.webjars.npm:electron