GHSA-547x-748v-vp6p
MODERATECVE-2024-21485Versions of the package dash-core-components before 2.13.0; versions of the package dash-core-components before 2.0.0; versions of the package dash before 2.15.0; versions of the package dash-html-components before 2.0.0; versions of the package dash-html-components before 2.0.16 are vulnerable to Cross-site Scripting (XSS) when the href of the a tag is controlled by an adversary. An authenticated
- Affected
- < 2.0.16
- Fixed in
- 2.0.16
- Weakness
- CWE-79
- Published
- 2024-02-02
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference