Description
verdaccio before 3.12.0 allows XSS.
Remediation
References
https://github.com/verdaccio/verdaccio/security/advisories/GHSA-78j5-gcmf-vqc8
Related Vulnerabilities
CVE-2018-20677 Vulnerability in maven package org.webjars.npm:bootstrap
CVE-2020-36048 Vulnerability in maven package org.webjars.bower:engine.io
CVE-2023-39022 Vulnerability in maven package opensymphony:oscore
CVE-2019-14862 Vulnerability in maven package li.rudin.mavenjs:knockout
CVE-2023-1784 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-parent