Lucene search

K
osvGoogleOSV:GHSA-5F38-9JW2-6R6H
HistoryOct 12, 2021 - 4:22 p.m.

Cross-site Scripting in teddy

2021-10-1216:22:04
Google
osv.dev
12
cross-site scripting
teddy
templating language
input sanitization
type confusion vulnerability
software

EPSS

0.001

Percentile

43.8%

Teddy is a readable and easy to learn templating language. This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization when the model content is an array (instead of a string).

EPSS

0.001

Percentile

43.8%

Related for OSV:GHSA-5F38-9JW2-6R6H