@dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix. This vulnerability has been patched on version `0.1.0`. Users are advised to upgrade. Users unable to upgrade should limit untrusted user input to the `init` function.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Oct 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-09-01T19:35:09.224Z
Updated: 2024-10-01T13:08:08.826Z
Reserved: 2023-08-22T16:57:23.933Z
Link: CVE-2023-41049

Updated: 2024-08-02T18:46:11.758Z

Status : Modified
Published: 2023-09-01T20:15:07.873
Modified: 2024-11-21T08:20:27.487
Link: CVE-2023-41049

No data.