{"id":"GHSA-mvjj-gqq2-p4hw","summary":"Cross-Site Scripting in react-dom","details":"Affected versions of `react-dom` are vulnerable to Cross-Site Scripting (XSS). The package fails to validate attribute names in HTML tags which may lead to Cross-Site Scripting in specific scenarios. This may allow attackers to execute arbitrary JavaScript in the victim's browser. To be affected by this vulnerability, the application needs to:\n- be a server-side React app\n- be rendered to HTML using `ReactDOMServer`\n- include an attribute name from user input in an HTML tag\n\n\n## Recommendation\n\nIf you are using `react-dom` 16.0.x, upgrade to 16.0.1 or later.  \nIf you are using `react-dom` 16.1.x, upgrade to 16.1.2 or later.  \nIf you are using `react-dom` 16.2.x, upgrade to 16.2.1 or later.  \nIf you are using `react-dom` 16.3.x, upgrade to 16.3.3 or later.  \nIf you are using `react-dom` 16.4.x, upgrade to 16.4.2 or later.","aliases":["CVE-2018-6341"],"modified":"2023-11-08T04:00:21.209483Z","published":"2019-01-04T19:05:35Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:47:15Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-6341"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-mvjj-gqq2-p4hw"},{"type":"WEB","url":"https://reactjs.org/blog/2018/08/01/react-v-16-4-2.html"},{"type":"WEB","url":"https://snyk.io/vuln/npm:react-dom:20180802"},{"type":"WEB","url":"https://twitter.com/reactjs/status/1024745321987887104"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1421"}],"affected":[{"package":{"name":"react-dom","ecosystem":"npm","purl":"pkg:npm/react-dom"},"ranges":[{"type":"SEMVER","events":[{"introduced":"16.0.0"},{"fixed":"16.0.1"}]}],"versions":["16.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-mvjj-gqq2-p4hw/GHSA-mvjj-gqq2-p4hw.json"}},{"package":{"name":"react-dom","ecosystem":"npm","purl":"pkg:npm/react-dom"},"ranges":[{"type":"SEMVER","events":[{"introduced":"16.1.0"},{"fixed":"16.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-mvjj-gqq2-p4hw/GHSA-mvjj-gqq2-p4hw.json"}},{"package":{"name":"react-dom","ecosystem":"npm","purl":"pkg:npm/react-dom"},"ranges":[{"type":"SEMVER","events":[{"introduced":"16.2.0"},{"fixed":"16.2.1"}]}],"versions":["16.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-mvjj-gqq2-p4hw/GHSA-mvjj-gqq2-p4hw.json"}},{"package":{"name":"react-dom","ecosystem":"npm","purl":"pkg:npm/react-dom"},"ranges":[{"type":"SEMVER","events":[{"introduced":"16.3.0"},{"fixed":"16.3.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-mvjj-gqq2-p4hw/GHSA-mvjj-gqq2-p4hw.json"}},{"package":{"name":"react-dom","ecosystem":"npm","purl":"pkg:npm/react-dom"},"ranges":[{"type":"SEMVER","events":[{"introduced":"16.4.0"},{"fixed":"16.4.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-mvjj-gqq2-p4hw/GHSA-mvjj-gqq2-p4hw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}