CVE-2019-13506: XSS
Published Jul 11, 2019
·Updated
@nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS.
Affected Software
2 affected components
NuxtJS \@nuxt\/devalue Node.js<1.2.3
NuxtJS Nuxt.js Node.js<2.6.2
Remediation
Patch Available
Event History
Jul 11, 2019
CVE Published
via MITRE·01:07 PM
Data Sourced
via MITRE·01:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13506?
CVE-2019-13506 has a medium severity rating due to its potential to lead to Cross-Site Scripting (XSS) attacks.
2
How do I fix CVE-2019-13506?
To fix CVE-2019-13506, update the @nuxt/devalue package to version 1.2.3 or later and ensure Nuxt.js is updated to version 2.6.2 or later.
3
What types of vulnerabilities does CVE-2019-13506 address?
CVE-2019-13506 addresses vulnerabilities related to XSS caused by mishandling object keys in the @nuxt/devalue package.
4
Which versions of Nuxt.js are affected by CVE-2019-13506?
CVE-2019-13506 affects all versions of Nuxt.js before 2.6.2.
5
What is the impact of CVE-2019-13506 on applications?
The impact of CVE-2019-13506 can lead to unauthorized script execution in the context of a user's browser, compromising the security of web applications.