Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1qODctOHhmOC1mcDR3

Cross-Site Scripting in yui

Affected versions of yui are vulnerable to cross-site scripting in the uploader.swf and io.swf utilities, via script injection in the url.

Recommendation

YUI has published their recommendation to fix this issue.
Their recommendation is to:

Permalink: https://github.com/advisories/GHSA-mj87-8xf8-fp4w
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1qODctOHhmOC1mcDR3
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 4 years ago
Updated: about 2 years ago


EPSS Percentage: 0.00253
EPSS Percentile: 0.64513

Identifiers: GHSA-mj87-8xf8-fp4w, CVE-2013-4939
References: Blast Radius: 0.0

Affected Packages

npm:yui
Dependent packages: 87
Dependent repositories: 1,172
Downloads: 54,090 last month
Affected Version Ranges: < 3.10.2
Fixed in: 3.10.3
All affected versions: 3.5.0, 3.5.1, 3.6.0, 3.7.0, 3.7.1, 3.7.2, 3.7.3, 3.8.0, 3.8.1, 3.9.0, 3.9.1, 3.10.0, 3.10.1
All unaffected versions: 3.10.2, 3.10.3, 3.11.0, 3.12.0, 3.13.0, 3.14.0, 3.14.1, 3.15.0, 3.16.0, 3.17.0, 3.17.1, 3.17.2, 3.18.0, 3.18.1