VYPR
Vendor

Finastra

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2022-24718HigMar 1, 2022
    risk 0.49cvss 7.6epss 0.01

    ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.4, a path traversal issue can occur when providing untrusted input to the `svg` property as an argument to the `build(MessagePageOptions)` function. While there is no known…

  • CVE-2022-31070MedJun 15, 2022
    risk 0.38cvss 5.8epss 0.01

    NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not have a way to block sensitive cookies (e.g. session cookies) from being forwarded to backend services configured by the application developer. This could have…

  • CVE-2022-31069MedJun 15, 2022
    risk 0.38cvss 5.8epss 0.01

    NestJS Proxy is a NestJS module to decorate and proxy calls. Prior to version 0.7.0, the nestjs-proxy library did not have a way to control when Authorization headers should should be forwarded for specific backend services configured by the application developer. This could…

  • CVE-2022-24717MedMar 1, 2022
    risk 0.33cvss 6.1epss 0.01

    ssr-pages is an HTML page builder for the purpose of server-side rendering (SSR). In versions prior to 0.1.5, a cross site scripting (XSS) issue can occur when providing untrusted input to the `redirect.link` property as an argument to the `build(MessagePageOptions)` function.…