CVE-2016-10547
Cross-Site Scripting in nunjucks
EPSS 0.38%
描述
Affected versions of `nunjucks` do not properly escape specially structured user input in template vars when in auto-escape mode, resulting in a cross-site scripting vulnerability. ## Proof of Concept By using an array for the keys in a template var, escaping is bypassed. ```javascript name[]=<script>alert(1)</script> ``` A full PoC is available in the references section. ## Recommendation Update to version 2.4.3 or later.
如何修補 CVE-2016-10547
要修補 CVE-2016-10547,請將受影響套件升級到下列已修補版本。
- npm/nunjucks—升級至 2.4.3 或更新版本
CVE-2016-10547 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2.4.3