Description
Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XSS) bug. We recommend upgrading to version 0.0.20 of the extension.
Remediation
References
https://github.com/GoogleChromeLabs/critters/security/advisories/GHSA-cx3j-qqxj-9597
Related Vulnerabilities
CVE-2016-2171 Vulnerability in maven package org.apache.portals.jetspeed-2:jetspeed-security
CVE-2011-4838 Vulnerability in maven package org.jruby:jruby-core
CVE-2016-6659 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-uaa
CVE-2023-34234 Vulnerability in npm package @openzeppelin/contracts
CVE-2023-29215 Vulnerability in maven package org.apache.linkis:linkis-metadata-query-service-jdbc