ids-enterprise@4.20.0-dev.20190724 vulnerabilities

Infor Design System (IDS) Enterprise Components for the web

Direct Vulnerabilities

Known vulnerabilities in the ids-enterprise package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cross-site Scripting (XSS)

ids-enterprise is a framework-independent UI library consisting of CSS and JS that provides product development teams, partners, and customers the tools to create user experiences that are approachable, focused, relevant, perceptive.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). Script tags inside dropdown options are executed when removing search text using backspace, resulting in execution of JavaScript.

How to fix Cross-site Scripting (XSS)?

Upgrade ids-enterprise to version 4.23.0-dev.20191105 or higher.

<4.23.0-dev.20191105
  • M
Cross-site Scripting (XSS)

ids-enterprise is a framework-independent UI library consisting of CSS and JS that provides product development teams, partners, and customers the tools to create user experiences that are approachable, focused, relevant, perceptive.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS). The title and title example value of a modal was found to be unescaped, allowing insertion of JavaScript which is not sanitized.

How to fix Cross-site Scripting (XSS)?

Upgrade ids-enterprise to version 4.22.0-beta.0 or higher.

<4.22.0-beta.0