GHSA-2ggq-vfcp-gwhj
UNKNOWNVersions of @hapi/boom prior to 0.3.8 are vulnerable to Cross-Site Scripting (XSS). The package fails to properly escape error messages, which may allow attackers to execute arbitrary JavaScript in a victim's browser.
- Affected
- >=0, <0.3.8
- Fixed in
- not stated
- Weakness
- CWE-79
- Published
- 2020-09-04
- Source
- osv