We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
漏洞描述如下: 高危 QAXOSS-2021-026725 利用难度:未知 发布日期:2021-09-13 CNNVD编号:未知 QAXOSS编号:QAXOSS-2021-026725 漏洞名称:xss正则表达式拒绝服务漏洞 CVSS:未知
影响版本:xss1.0.8、xss0.3.3 解决方案: 升级版本:v1.0.10 相关commit:leizongmin/js-xss@699acde 漏洞补丁:leizongmin/js-xss@699acde 参考方案:Upgrade xss to version 1.0.10 or higher. 缓解方案:暂无缓解方案
组件版本使用建议 推荐使用版本:1.0.10 最新发布版本:1.0.15
The text was updated successfully, but these errors were encountered:
cr
Sorry, something went wrong.
已修复,待新版本发布
No branches or pull requests
版本号:1.9.4
问题描述:安全检测发现1.9.4对应的springboot3版本存在组件高危漏洞,该组件为js组件,xss:0.3.3,建议是否可以尝试升级为1.0.10版本。
错误日志&截图:
重现步骤:使用奇安信开源卫士检测发现高危漏洞,经过排查法发现,移除积木报表后漏洞消失,判断该漏洞为积木报表中自带的js组件导致的,建议尝试升级为1.0.10版本。
漏洞描述如下:
高危
QAXOSS-2021-026725 利用难度:未知 发布日期:2021-09-13
CNNVD编号:未知
QAXOSS编号:QAXOSS-2021-026725
漏洞名称:xss正则表达式拒绝服务漏洞
CVSS:未知
影响版本:xss1.0.8、xss0.3.3
解决方案:
升级版本:v1.0.10
相关commit:leizongmin/js-xss@699acde
漏洞补丁:leizongmin/js-xss@699acde
参考方案:Upgrade xss to version 1.0.10 or higher.
缓解方案:暂无缓解方案
组件版本使用建议
推荐使用版本:1.0.10
最新发布版本:1.0.15
友情提示(为了提高issue处理效率):
The text was updated successfully, but these errors were encountered: