Description
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.
Remediation
References
https://github.com/karma-runner/karma/commit/839578c45a8ac42fbc1d72105f97eab77dd3eb8a
https://huntr.dev/bounties/64b67ea1-5487-4382-a5f6-e8a95f798885
Related Vulnerabilities
CVE-2022-36894 Vulnerability in maven package org.jenkins-ci.plugins:clif-performance-testing
CVE-2023-22461 Vulnerability in npm package @mattkrick/sanitize-svg
CVE-2021-37694 Vulnerability in npm package @asyncapi/java-spring-cloud-stream-template
CVE-2020-28452 Vulnerability in maven package com.softwaremill.akka-http-session:core_2.12
CVE-2023-46604 Vulnerability in maven package org.apache.activemq:activemq-openwire-legacy