Description
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.
Remediation
References
https://github.com/karma-runner/karma/commit/839578c45a8ac42fbc1d72105f97eab77dd3eb8a
https://huntr.dev/bounties/64b67ea1-5487-4382-a5f6-e8a95f798885
Related Vulnerabilities
CVE-2022-39299 Vulnerability in npm package passport-saml
CVE-2023-40340 Vulnerability in maven package org.jenkins-ci.plugins:nodejs
CVE-2020-15092 Vulnerability in npm package @knight-lab/timelinejs
CVE-2018-8013 Vulnerability in maven package org.eclipse.birt.runtime:org.apache.batik.dom
CVE-2022-1291 Vulnerability in maven package org.webjars.npm:tableexport.jquery.plugin