REDHAT-BUG-2484124: XSS
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in version 7.13.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.13.2
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2484124?
The severity of REDHAT-BUG-2484124 is medium, rated at 4.
What versions are affected by REDHAT-BUG-2484124?
REDHAT-BUG-2484124 affects React Router versions 7.7.0 through 7.13.1.
How can I mitigate the XSS vulnerability in REDHAT-BUG-2484124?
To mitigate the XSS vulnerability in REDHAT-BUG-2484124, avoid using untrusted sources for redirects in your React applications.
Is REDHAT-BUG-2484124 related to Cross-Site Scripting (XSS)?
Yes, REDHAT-BUG-2484124 involves a potential client-side Cross-Site Scripting (XSS) vulnerability due to improper redirect handling.
What are the potential impacts of REDHAT-BUG-2484124?
The potential impacts of REDHAT-BUG-2484124 include exploitation of XSS vulnerabilities when untrusted redirect sources are used in React applications.