Description
verdaccio before 3.12.0 allows XSS.
Remediation
References
https://github.com/verdaccio/verdaccio/security/advisories/GHSA-78j5-gcmf-vqc8
Related Vulnerabilities
CVE-2022-2216 Vulnerability in npm package parse-url
CVE-2021-21344 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2021-29369 Vulnerability in npm package gnuplot
CVE-2021-38542 Vulnerability in maven package org.apache.james:james-server
CVE-2018-15685 Vulnerability in maven package org.webjars.npm:electron