Description
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.
Remediation
References
https://github.com/karma-runner/karma/commit/839578c45a8ac42fbc1d72105f97eab77dd3eb8a
https://huntr.dev/bounties/64b67ea1-5487-4382-a5f6-e8a95f798885
Related Vulnerabilities
CVE-2021-43849 Vulnerability in npm package cordova-plugin-fingerprint-aio
CVE-2021-21428 Vulnerability in maven package org.openapitools:openapi-generator-online
CVE-2022-38666 Vulnerability in maven package io.jenkins.plugins:cavisson-ns-nd-integration
CVE-2014-3574 Vulnerability in maven package org.apache.poi:poi-ooxml
CVE-2016-2164 Vulnerability in maven package org.apache.openmeetings:openmeetings-server