EIQ-2019-0023
    
| 
     ID  | 
                
     EIQ-2019-0023  | 
        
| 
     CVE  | 
                
     -  | 
        
| 
     Description  | 
                
     Cross-site scripting (XSS) vulnerability in webpack bundle analyzer  | 
        
| 
     Date  | 
                
     29 Apr 2019  | 
        
| 
     Severity  | 
                
     2 - MEDIUM  | 
        
| 
     CVSSv3 score  | 
                
     CVSSv3 score not available on NIST NVD.  | 
        
| 
     Status  | 
                
     
  | 
        
| 
     Assessment  | 
                
     webpack bundle analyzer versions 3.3.1 and earlier is vulnerable to cross-site scripting (XSS). An attacker could exploit improper input sanitization to inject malicious code, which JSON.stringify could pass with parameter functions such as chartData, enableWebSocket, or defaultSizes.  | 
        
| 
     Mitigation  | 
                
     Upgrade webpack bundle analyzer to version 3.3.2 or later.  | 
        
| 
     Affected versions  | 
                
     2.4.0 and earlier.  | 
        
| 
     Notes  | 
                
     For more information, see:  | 
        
< Back to all security issues and mitigation actions
In release notes 2.4.0
In release notes 2.5.0