Description
Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XSS) bug. We recommend upgrading to version 0.0.20 of the extension.
Remediation
References
https://github.com/GoogleChromeLabs/critters/security/advisories/GHSA-cx3j-qqxj-9597
Related Vulnerabilities
CVE-2022-32533 Vulnerability in maven package org.apache.portals.jetspeed-2:jetspeed
CVE-2012-3536 Vulnerability in maven package org.apache.james.hupa:hupa-server
CVE-2017-3159 Vulnerability in maven package org.apache.camel:camel-snakeyaml
CVE-2022-42125 Vulnerability in maven package com.liferay.portal:com.liferay.portal.impl