Vulnerabilities (CVE)

Filtered by vendor Less-openui5 Project
Filtered by product Less-openui5
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-21316 1 Less-openui5 Project 1 Less-openui5 2024-11-21 6.8 MEDIUM 6.3 MEDIUM
less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10., when processing theming resources (i.e. `*.less` files) with less-openui5 that originate from an untrusted source, those resources might contain JavaScript code which will be executed in the context of the build process. While this is a feature of the Less.js library it is an unexpected behavior in the context of OpenUI5 and SAPUI5 development. Especially in the context of UI5 ...

Show More