Cross-Site Scripting (XSS) Vulnerability in ReactDOMServer API

Cross-Site Scripting (XSS) Vulnerability in ReactDOMServer API

CVE-2018-6341 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:P/A:N

React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.

Learn more about our Cis Benchmark Audit For Server Software.