PT-2022-16818 · Amazon · @Awsui/Components-React

Fralongopublished

·

Published

2022-02-24

·

Updated

2022-03-08

·

CVE-2022-24709

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @awsui/components-react versions prior to 3.0.367
Description The issue concerns multiple components in the @awsui/components-react package that do not properly neutralize user input, potentially allowing for javascript injection. This could lead to cross-site scripting (XSS) in certain circumstances, as the components may render content without adequate neutralization.
Recommendations For versions prior to 3.0.367, upgrade to version 3.0.367 or later to resolve the issue. As a temporary workaround, consider restricting the use of the vulnerable components until a patch is applied. There are no known workarounds for this issue other than upgrading to the fixed version.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24709
GHSA-MF22-92PM-M8P8

Affected Products

@Awsui/Components-React