ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path traversal issue can occur when providing untrusted input to the `svg` property as an argument to the `build(MessagePageOptions)` function. While there is no known workaround at this time, there is a patch in version 0.1.4.
References
Link | Resource |
---|---|
https://github.com/Finastra/ssr-pages/pull/1 | Patch Third Party Advisory |
https://github.com/Finastra/ssr-pages/pull/1/commits/c3e4c563384ae3ba3892f37dd190218577620780 | Patch Third Party Advisory |
https://github.com/Finastra/ssr-pages/security/advisories/GHSA-w6cx-qg2q-rvq8 | Patch Third Party Advisory |
Configurations
History
No history.
Information
Published : 2022-03-01 19:15
Updated : 2024-02-28 19:09
NVD link : CVE-2022-24718
Mitre link : CVE-2022-24718
CVE.ORG link : CVE-2022-24718
JSON object : View
Products Affected
finastra
- ssr-pages
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')