Description
XSS exists in Shave before 2.5.3 because output encoding is mishandled during the overwrite of an HTML element.
Remediation
References
https://github.com/dollarshaveclub/shave/commit/da7371b0531ba14eae48ef1bb1456a3de4cfa954#diff-074799b511e4b61923dfd3f2a3bf9b54R67
https://github.com/dollarshaveclub/shave/compare/852b537...da7371b
https://www.npmjs.com/advisories/822
Related Vulnerabilities
CVE-2022-34298 Vulnerability in maven package org.openidentityplatform.openam:openam-auth-nt
CVE-2021-23901 Vulnerability in maven package org.apache.nutch:nutch
CVE-2021-41184 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery-ui
CVE-2023-36106 Vulnerability in maven package tech.powerjob:powerjob
CVE-2021-37404 Vulnerability in maven package org.apache.hadoop:hadoop-hdfs-native-client