Description
React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mvjj-gqq2-p4hw | Cross-Site Scripting in react-dom |
References
History
Tue, 06 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2025-05-06T16:54:17.932Z
Reserved: 2018-01-26T00:00:00.000Z
Link: CVE-2018-6341
Updated: 2024-08-05T06:01:48.794Z
Status : Modified
Published: 2018-12-31T22:29:00.387
Modified: 2025-05-06T17:15:51.207
Link: CVE-2018-6341
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA