EIQ-2019-0023
    
| ID | EIQ-2019-0023 | 
| CVE | - | 
| Description | Cross-site scripting (XSS) vulnerability in webpack bundle analyzer | 
| Date | 29 Apr 2019 | 
| Severity | 2 - MEDIUM | 
| CVSSv3 score | CVSSv3 score not available on NIST NVD. | 
| Status | 
 | 
| Assessment | webpack bundle analyzer versions 3.3.1 and earlier is vulnerable to cross-site scripting (XSS). An attacker could exploit improper input sanitization to inject malicious code, which JSON.stringify could pass with parameter functions such as chartData, enableWebSocket, or defaultSizes. | 
| Mitigation | Upgrade webpack bundle analyzer to version 3.3.2 or later. | 
| Affected versions | 2.4.0 and earlier. | 
| Notes | For more information, see: | 
< Back to all security issues and mitigation actions
In release notes 2.4.0
In release notes 2.5.0