{"id":"GHSA-vwhg-jwr4-vxgg","summary":"gettext.js has a Cross-site Scripting injection ","details":"### Impact\nPossible vulnerability to XSS injection if .po dictionary definition files is corrupted\n\n### Patches\nUpdate gettext.js to 2.0.3\n\n### Workarounds\nMake sure you control the origin of the definition catalog to prevent the use of this flaw in the definition of plural forms.\n","aliases":["CVE-2024-43370"],"modified":"2024-08-16T18:15:39Z","published":"2024-08-15T18:06:50Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-08-15T18:06:50Z","nvd_published_at":"2024-08-16T02:15:17Z"},"references":[{"type":"WEB","url":"https://github.com/guillaumepotier/gettext.js/security/advisories/GHSA-vwhg-jwr4-vxgg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-43370"},{"type":"WEB","url":"https://github.com/guillaumepotier/gettext.js/commit/8150aeba833183e14c2291a8a148b8f79d1d68d8"},{"type":"PACKAGE","url":"https://github.com/guillaumepotier/gettext.js"}],"affected":[{"package":{"name":"gettext.js","ecosystem":"npm","purl":"pkg:npm/gettext.js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.0.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-vwhg-jwr4-vxgg/GHSA-vwhg-jwr4-vxgg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"}]}