ansibleguy-webui@0.0.22.post2 vulnerabilities

Basic WebUI for using Ansible

  • latest version

    0.0.25

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    3 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the ansibleguy-webui package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Cross-site Scripting (XSS)

    ansibleguy-webui is a Basic WebUI for using Ansible

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) insufficient input sanitization when handling and displaying regex patterns.

    Note: The commit fix partially addresses this vulnerability by introducing escaping mechanisms and input validation

    How to fix Cross-site Scripting (XSS)?

    Upgrade ansibleguy-webui to version 0.0.23.post3 or higher.

    [,0.0.23.post3)
    • M
    Cross-site Scripting (XSS)

    ansibleguy-webui is a Basic WebUI for using Ansible

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in edit.js, which does not escape quote characters.

    How to fix Cross-site Scripting (XSS)?

    Upgrade ansibleguy-webui to version 0.0.23.post3 or higher.

    [,0.0.23.post3)