VYPR

Node Red Dashboard

by Nodered

Source repositories

CVEs (3)

  • CVE-2021-3223HigJan 26, 2021
    risk 0.43cvss 7.5epss 0.19

    Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.

  • CVE-2019-10756MedOct 8, 2019
    risk 0.35cvss 5.4epss 0.01

    It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.

  • CVE-2022-3783LowOct 31, 2022
    risk 0.16cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The manipulation leads to cross site…