Description
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SCULLYIOSCULLY-1055829
https://github.com/scullyio/scully/pull/1182
Related Vulnerabilities
CVE-2022-43413 Vulnerability in maven package org.jenkins-ci.plugins:job-import-plugin
CVE-2017-12634 Vulnerability in maven package org.apache.camel:camel-castor
CVE-2018-20677 Vulnerability in maven package org.webjars:bootstrap
CVE-2020-2110 Vulnerability in maven package org.jenkins-ci.plugins:script-security
CVE-2019-10431 Vulnerability in maven package org.jenkins-ci.plugins:script-security