4.3
CVSSv2

CVE-2018-6341

Published: 31/12/2018 Updated: 09/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

facebook react

Github Repositories

CVE-2018-6341

CVE-2018-6341 cvemitreorg/cgi-bin/cvenamecgi?name=CVE-2018-6341 A simple PoC to reproduce XSS vulnerability Steps npm i npm run start Go to localhost:3006

How to run Scratch 3 localy in Docker (aka one of many solutions for sad Linux mates)

My friend become sad because there is no offline version of recently released Scratch 3 So, here is recipe how he (and you!) can run Scratch 3 on your own Linux computer How to build Scratch 3 Docker image Install Docker, clone this repository and run: $ /buildsh You should see something like this: Cloning into 'scratch-gui'

react react-dom react-changelog new

react-changelogs 注意⚠️: 下面只是做了简单的翻译,每条日志更新的具体信息请访问具体的Pull requests 1686 (2019-03-27) React DOM 修复在usereducer()中错误的紧急援助。(@acdlite in #15124) 修复safari浏览器中devtools中的iframe警告。(@renanvalentin in #15099) 如果contextType设置为ContextConsumer而不是Context,

Uma mostra evolutiva das versões do react retirado do próprio projeto react

release-notes-react Uma mostra evolutiva das versões do react retirado do próprio projeto react 1800 (March 29, 2022) Below is a list of all new features, APIs, deprecations, and breaking changes Read React 18 release post and React 18 upgrade guide for more information New Features React useId is a new hook for generating unique IDs on both the client and se