{"id":"GHSA-2ggq-vfcp-gwhj","aliases":[],"url":"https://o3.security/vulnerability/GHSA-2ggq-vfcp-gwhj","summary":"Cross-Site Scripting in @hapi/boom","details":"Versions of `@hapi/boom` prior to 0.3.8 are vulnerable to Cross-Site Scripting (XSS). The package fails to properly escape error messages, which may allow attackers to execute arbitrary JavaScript in a victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 0.3.8 or later.","published":"2020-09-04T17:33:53Z","modified":"2023-10-02T18:43:16Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"@hapi/boom","fixedVersion":"0.3.8"}],"fix":{"url":"https://github.com/hapijs/boom/commit/0f8640bdba65aec6e6799bfc16ff5753150bfcaf","label":"hapijs/boom@0f8640b"},"references":[{"type":"WEB","url":"https://github.com/hapijs/boom/commit/0f8640bdba65aec6e6799bfc16ff5753150bfcaf"},{"type":"PACKAGE","url":"https://github.com/hapijs/boom"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-HAPIBOOM-541183"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-10-02T18:43:16Z"}}