CVE-2024-43370
gettext.js vulnerable to cross-site scripting (XSS)
gettext.js is a GNU gettext port for node and the browser. There is a cross-site scripting (XSS) injection if `.po` dictionary definition files are corrupted. This vulnerability has been patched in version 2.0.3. As a workaround, control the origin of the definition catalog to prevent the use of this flaw in the definition of plural forms.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Productos afectados
guillaumepotier · gettext.js¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →