Vulnerabilities
3 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-37602 | Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js. Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js. NVD description · AI analysis pending | 9.8 | 2% | PoC ×2 |
| — | |
| CVE-2021-23495 | The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter. The package karma before 6.3.16 are vulnerable to Open Redirect due to missing validation of the return_url query parameter. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2022-0437 | Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14. Cross-site Scripting (XSS) - DOM in NPM karma prior to 6.3.14. NVD description · AI analysis pending | 6.1 | 15% | PoC |
| — |