Vulnerabilities (CVE)

Filtered by vendor Owasp
Filtered by product Dependency-track Frontend
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-39350 1 Owasp 1 Dependency-track Frontend 2024-11-21 N/A 5.4 MEDIUM
@dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain. Due to the common practice of providing vulnerability details in markdown format, the Dependency-Track frontend renders them using the JavaScript library Showdown. Showdown does not have any XSS countermeasures built in, and versions before 4.6.1 of the Dependency-Track frontend did no ...

Show More