CVE-2022-4414: Cross-site Scripting (XSS) - DOM in nuxt/framework
Published Dec 11, 2022
·Updated
Cross-site Scripting (XSS) - DOM in GitHub repository nuxt/framework prior to v3.0.0-rc.13.
Affected Software
12 affected components
Nuxt framework=3.0.0-rc1
Nuxt framework=3.0.0-rc10
Nuxt framework=3.0.0-rc11
Nuxt framework=3.0.0-rc12
Nuxt framework=3.0.0-rc2
Nuxt framework=3.0.0-rc3
Nuxt framework=3.0.0-rc4
Nuxt framework=3.0.0-rc5
Nuxt framework=3.0.0-rc6
Nuxt framework=3.0.0-rc7
Nuxt framework=3.0.0-rc8
Nuxt framework=3.0.0-rc9
Remediation
Event History
Dec 11, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Dec 12, 2022
Data Sourced
via NVD·12:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-4414?
CVE-2022-4414 is a Cross-site Scripting (XSS) vulnerability in the nuxt/framework GitHub repository prior to v3.0.0-rc.13.
2
What is the severity of CVE-2022-4414?
The severity of CVE-2022-4414 is medium with a CVSS score of 6.1.
3
What is the affected software for CVE-2022-4414?
The affected software for CVE-2022-4414 is Nuxt Framework versions 3.0.0-rc1 to 3.0.0-rc12.
4
How can I fix CVE-2022-4414?
To fix CVE-2022-4414, you should update to Nuxt Framework v3.0.0-rc.13 or later.
5
Where can I find more information about CVE-2022-4414?
You can find more information about CVE-2022-4414 in the references: [GitHub Commit](https://github.com/nuxt/framework/commit/19a2cd14929ca9b55720cb81f71687830a9e59a4), [Huntr.dev Bounty](https://huntr.dev/bounties/131a41e5-c936-4c3f-84fc-e0e1f0e090b5).