VDB
CVE-2023-3481
CVE-2023-3481
PUBLISHED
CVSS 5.699999809265137 MEDIUM
Critters versions 0.0.17-0.0.19 have an issue when parsing the HTML, which leads to a potential cross-site scripting (XSS) bug. We recommend upgrading to version 0.0.20 of the extension.
EPSS 0.17% · 6.7th percentile
Risk Scores
CVSS 3.1
5.699999809265137
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
EPSS Score
0.17%
6.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| npm | critters | 0.0.17 |
| Google Chrome Labs | Critters | 0.0.17 |
| critters | 0.0.17 |
Timeline
- Aug 11, 2023 CVE Published
- Aug 22, 2023 EPSS Score
- Sep 24, 2023 EPSS Score
- Oct 28, 2023 EPSS Score
- Nov 30, 2023 EPSS Score
- Jan 2, 2024 EPSS Score
- Feb 5, 2024 EPSS Score
- Mar 9, 2024 EPSS Score
- Apr 11, 2024 EPSS Score
- May 15, 2024 EPSS Score
- Jun 17, 2024 EPSS Score
- Jul 20, 2024 EPSS Score
References
- https://github.com/GoogleChromeLabs/critters/security/advisories/GHSA-cx3j-qqxj-9597 url
- https://nvd.nist.gov/vuln/detail/CVE-2023-3481 advisory
- https://github.com/GoogleChromeLabs/critters/pull/133 url
- https://github.com/GoogleChromeLabs/critters/commit/7757902c9e0b3285d516359b3cb602cd9d50d80e url
- https://github.com/GoogleChromeLabs/critters package