CVE-2019-13506
11.07.2019, 14:15
@nuxt/devalue before 1.2.3, as used in Nuxt.js before 2.6.2, mishandles object keys, leading to XSS.
Vendor | Product | Version |
---|---|---|
nuxtjs | \@nuxt\/devalue | 𝑥 < 1.2.3 |
nuxtjs | nuxt.js | 𝑥 < 2.6.2 |
𝑥
= Vulnerable software versions
References