漏洞描述
npm package ansi_up v4 is vulnerable to cross-site scripting because ANSI escape codes can be used to create HTML hyperlinks.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
doyensec.comhttps://doyensec.com/resources/Doyensec_Advisory_ansi_up4_XSS.pdf↗github.comhttps://github.com/drudru/ansi_up/commit/c8c726ed1db979bae4f257b7fa41775155ba2e27↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2021-3377↗github.comhttps://github.com/ARPSyndicate/kenzer-templates↗github.comhttps://github.com/ARPSyndicate/cvemon↗