{"id":"GHSA-cfxh-frx4-9gjg","summary":"Cross-site Scripting in @spscommerce/ds-react","details":"### Impact\nXSS, anyone using the SPS Select with options prop populated from user input is impacted. If these options are stored, then it could have been a stored XSS. \n\n### Patches\nThe code has been patched for version 7 of woodland. Users should upgrade to 7.17.4 or higher\n\n### Workarounds\nThis is not recommended. If you are not upgrading then you would need to sanitize your options yourself (including those currently stored in databases). This is not recommended.\n\n### References\nhttps://github.com/SPSCommerce/woodland/blob/c49e999f97f3c0b56502859f4de1e8c6666dd74d/packages/ds-react/src/option-list/SpsOptionList.tsx#L559\n","modified":"2023-12-15T03:13:18Z","published":"2023-12-15T03:13:18Z","database_specific":{"github_reviewed_at":"2023-12-15T03:13:18Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/SPSCommerce/woodland/security/advisories/GHSA-cfxh-frx4-9gjg"},{"type":"PACKAGE","url":"https://github.com/SPSCommerce/woodland"}],"affected":[{"package":{"name":"@spscommerce/ds-react","ecosystem":"npm","purl":"pkg:npm/%40spscommerce/ds-react"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.12.2"},{"fixed":"7.17.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/12/GHSA-cfxh-frx4-9gjg/GHSA-cfxh-frx4-9gjg.json"}}],"schema_version":"1.9.0"}