First published: Thu Feb 24 2022(Updated: )
@awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface development. Multiple components in versions before 3.0.367 have been found to not properly neutralize user input and may allow for javascript injection. Users are advised to upgrade to version 3.0.367 or later. There are no known workarounds for this issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Awsui\/components-react | <3.0.367 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-24709.
The severity of CVE-2022-24709 is high with a CVSS score of 6.1.
The affected software is @awsui/components-react version up to and exclusive of 3.0.367.
CVE-2022-24709 is a javascript injection vulnerability.
You can find more information about CVE-2022-24709 in the following references: [1](https://github.com/aws/awsui-documentation/security/advisories/GHSA-mf22-92pm-m8p8), [2](https://www.npmjs.com/package/@awsui/components-react)