Medium severity6.1NVD Advisory· Published Mar 1, 2022· Updated Jun 17, 2026
CVE-2022-24717
CVE-2022-24717
Description
ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.5, a cross site scripting (XSS) issue can occur when providing untrusted input to the redirect.link property as an argument to the build(MessagePageOptions) function. While there is no known workaround at this time, there is a patch in version 0.1.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@finastra/ssr-pagesnpm | < 0.1.5 | 0.1.5 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/Finastra/ssr-pages/commit/98abc59e28fec48246be0d59ac144675d6361073nvdPatchThird Party AdvisoryWEB
- github.com/Finastra/ssr-pages/pull/2nvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/Finastra/ssr-pages/pull/2/commits/133606ffaec2edd9918d9fba5771ed21da7876a5nvdPatchThird Party AdvisoryWEB
- github.com/Finastra/ssr-pages/security/advisories/GHSA-7f63-h6g3-7cwmnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-7f63-h6g3-7cwmghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-24717ghsaADVISORY
News mentions
0No linked articles in our index yet.