{"id":"GHSA-7x7c-qm48-pq9c","summary":"Cross-site Scripting in karma","details":"karma prior to version 6.3.14 contains a cross-site scripting vulnerability.","aliases":["CVE-2022-0437"],"modified":"2023-11-01T04:57:06.865543Z","published":"2022-02-06T00:00:54Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-02-07T21:57:20Z","nvd_published_at":"2022-02-05T02:15:00Z","cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0437"},{"type":"WEB","url":"https://github.com/karma-runner/karma/commit/839578c45a8ac42fbc1d72105f97eab77dd3eb8a"},{"type":"WEB","url":"https://github.com/karma-runner/karma"},{"type":"WEB","url":"https://github.com/karma-runner/karma/releases/tag/v6.3.14"},{"type":"WEB","url":"https://huntr.dev/bounties/64b67ea1-5487-4382-a5f6-e8a95f798885"}],"affected":[{"package":{"name":"karma","ecosystem":"npm","purl":"pkg:npm/karma"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.3.14"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-7x7c-qm48-pq9c/GHSA-7x7c-qm48-pq9c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}