References https://github.com/advisories/GHSA-7x7c-qm48-pq9c https://nvd.nist.gov/vuln/detail/CVE-2022-0437 https://access.redhat.com/security/cve/cve-2022-0437 https://cve.circl.lu/cve/CVE-2022-0437 https://www.sentinelone.com/vulnerability-database/cve-2022-0437/ https://www.acunetix.com/vulnerabilities/sca/cve-2022-0437-vulnerability-in-npm-package-karma/ https://snyk.io/node-js/karma
Related VulnerabilitiesPoCCVE-2022-0437: karma-runner DOM-based Cross-Site ScriptingPoCCVE-2022-0692: Rudloff alltube prior to 3.0.1 - Open RedirectPoCCVE-2021-21402: Jellyfin prior to 10.7.0 Unauthenticated Arbitrary File ReadPoCkarma-config-js: Karma Configuration File - DetectPackagist microweber prior 反射型跨站脚本漏洞CrushFTP prior CVE-2023-43177 远程代码执行漏洞畅捷通T+ Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx 命令执行