Skip to content
This repository has been archived by the owner on Oct 27, 2020. It is now read-only.

Update dependency react-dom to v16.4.2 [SECURITY] #59

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Aug 23, 2019

This PR contains the following updates:

Package Type Update Change
react-dom (source) dependencies patch 16.4.1 -> 16.4.2

GitHub Vulnerability Alerts

CVE-2018-6341

Affected versions of react-dom are vulnerable to Cross-Site Scripting (XSS). The package fails to validate attribute names in HTML tags which may lead to Cross-Site Scripting in specific scenarios. This may allow attackers to execute arbitrary JavaScript in the victim's browser. To be affected by this vulnerability, the application needs to:

  • be a server-side React app
  • be rendered to HTML using ReactDOMServer
  • include an attribute name from user input in an HTML tag

Recommendation

If you are using react-dom 16.0.x, upgrade to 16.0.1 or later.
If you are using react-dom 16.1.x, upgrade to 16.1.2 or later.
If you are using react-dom 16.2.x, upgrade to 16.2.1 or later.
If you are using react-dom 16.3.x, upgrade to 16.3.3 or later.
If you are using react-dom 16.4.x, upgrade to 16.4.2 or later.


Release Notes

facebook/react

v16.4.2

Compare Source

React DOM Server

Renovate configuration

📅 Schedule: "" (UTC).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻️ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by WhiteSource Renovate. View repository job log here.

@renovate renovate bot force-pushed the renovate/npm-react-dom-vulnerability branch from 7ede5e6 to 729d76d Compare October 4, 2019 11:54
@renovate renovate bot force-pushed the renovate/npm-react-dom-vulnerability branch from 729d76d to fe649bb Compare November 12, 2019 05:00
@renovate renovate bot force-pushed the renovate/npm-react-dom-vulnerability branch from fe649bb to d7c66e0 Compare November 21, 2019 13:21
@renovate renovate bot force-pushed the renovate/npm-react-dom-vulnerability branch from d7c66e0 to bad7b58 Compare December 21, 2019 23:53
@renovate renovate bot force-pushed the renovate/npm-react-dom-vulnerability branch from bad7b58 to ceab7a6 Compare March 14, 2020 23:59
@renovate renovate bot force-pushed the renovate/npm-react-dom-vulnerability branch from ceab7a6 to 03e7b7f Compare April 28, 2020 06:00
@renovate renovate bot force-pushed the renovate/npm-react-dom-vulnerability branch from 03e7b7f to 5cbc43c Compare June 23, 2020 15:48
@renovate renovate bot force-pushed the renovate/npm-react-dom-vulnerability branch from 5cbc43c to e188d07 Compare July 1, 2020 22:54
@renovate renovate bot force-pushed the renovate/npm-react-dom-vulnerability branch from e188d07 to 1f10b6a Compare July 10, 2020 11:50
@renovate renovate bot force-pushed the renovate/npm-react-dom-vulnerability branch from 1f10b6a to dc28491 Compare August 25, 2020 01:53
@renovate renovate bot force-pushed the renovate/npm-react-dom-vulnerability branch from dc28491 to 126de49 Compare October 26, 2020 03:00
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant