Description
This affects all versions of package lightning-server. It is possible to inject malicious JavaScript code as part of a session controller.
Remediation
References
https://github.com/lightning-viz/lightning/blob/master/app/controllers/session.js
https://github.com/lightning-viz/lightning/blob/master/app/controllers/session.js%23L230
https://snyk.io/vuln/SNYK-JS-LIGHTNINGSERVER-1019381
Related Vulnerabilities
CVE-2022-36067 Vulnerability in npm package vm2
CVE-2021-36373 Vulnerability in maven package org.apache.ant:ant
CVE-2022-1291 Vulnerability in maven package org.webjars.bower:tableexport.jquery.plugin
CVE-2020-1956 Vulnerability in maven package org.apache.kylin:kylin-core-common
CVE-2022-23621 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore