Description
Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14.
Remediation
References
https://github.com/karma-runner/karma/commit/839578c45a8ac42fbc1d72105f97eab77dd3eb8a
https://huntr.dev/bounties/64b67ea1-5487-4382-a5f6-e8a95f798885
Related Vulnerabilities
CVE-2022-28220 Vulnerability in maven package org.apache.james.protocols:protocols-netty
CVE-2021-23648 Vulnerability in npm package @braintree/sanitize-url
CVE-2021-32809 Vulnerability in maven package org.webjars.bowergithub.ckeditor:ckeditor4
CVE-2022-39387 Vulnerability in maven package org.xwiki.contrib.oidc:oidc-authenticator
CVE-2023-32688 Vulnerability in npm package @parse/push-adapter