Description
This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.
Remediation
References
https://github.com/scullyio/scully/pull/1182
https://snyk.io/vuln/SNYK-JS-SCULLYIOSCULLY-1055829
Related Vulnerabilities
CVE-2023-40349 Vulnerability in maven package org.jenkins-ci.plugins:gogs-webhook
CVE-2023-40178 Vulnerability in npm package @node-saml/node-saml
CVE-2022-45399 Vulnerability in maven package org.zeroturnaround:cluster-stats
CVE-2014-7810 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2014-2064 Vulnerability in maven package org.jenkins-ci.main:jenkins-core