@dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix. This vulnerability has been patched on version `0.1.0`. Users are advised to upgrade. Users unable to upgrade should limit untrusted user input to the `init` function.
History

Tue, 01 Oct 2024 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2023-09-01T19:35:09.224Z

Updated: 2024-10-01T13:08:08.826Z

Reserved: 2023-08-22T16:57:23.933Z

Link: CVE-2023-41049

cve-icon Vulnrichment

Updated: 2024-08-02T18:46:11.758Z

cve-icon NVD

Status : Modified

Published: 2023-09-01T20:15:07.873

Modified: 2024-11-21T08:20:27.487

Link: CVE-2023-41049

cve-icon Redhat

No data.