Vulnerability Database
Blog
FAQ
Docs
GHSA-j3gg-r6gp-95q2
Suggest an improvement
Source
https://github.com/advisories/GHSA-j3gg-r6gp-95q2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-j3gg-r6gp-95q2/GHSA-j3gg-r6gp-95q2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j3gg-r6gp-95q2
Aliases
CVE-2021-46871
GHSA-5g2h-9x5v-5h3x
Published
2022-04-12T20:22:57Z
Modified
2023-11-08T04:07:27.432668Z
Summary
XSS in HEEx class attributes
Details
The
class
attribute was not protected against XSS attacks when using HEEx.
References
https://github.com/phoenixframework/phoenix_html/commit/62a0139fb716bcdce697f6221244bd81d321d620
https://github.com/phoenixframework/phoenix_html
Affected packages
Hex
/
phoenix_html
Package
Name
phoenix_html
Purl
pkg:hex/phoenix_html
Affected ranges
Type
SEMVER
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
3.0.4
GHSA-j3gg-r6gp-95q2 - OSV