« Volver al listado

CVE-2018-6341

Estado: ModificadaMedia (6.1)—

React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-6341",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2018-6341",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-05-06T16:54:12.196558Z"
        }
      }
    ],
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve-assign@fb.com",
      "affectedData": [
        {
          "vendor": "Facebook",
          "product": "react-dom",
          "versions": [
            {
              "status": "affected",
              "version": "16.4.2"
            },
            {
              "status": "affected",
              "version": "16.4.0",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "16.3.3"
            },
            {
              "status": "affected",
              "version": "16.3.0",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "16.2.1"
            },
            {
              "status": "affected",
              "version": "16.2.0",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "16.1.2"
            },
            {
              "status": "affected",
              "version": "16.1.0",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "16.0.1"
            },
            {
              "status": "affected",
              "version": "16.0.0",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "unspecified",
              "lessThan": "16.0.0",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-12-31T22:29:00.387",
  "references": [
    {
      "url": "https://reactjs.org/blog/2018/08/01/react-v-16-4-2.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve-assign@fb.com"
    },
    {
      "url": "https://twitter.com/reactjs/status/1024745321987887104",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve-assign@fb.com"
    },
    {
      "url": "https://reactjs.org/blog/2018/08/01/react-v-16-4-2.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://twitter.com/reactjs/status/1024745321987887104",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-assign@fb.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulnerability. This issue affected minor releases 16.0.x, 16.1.x, 16.2.x, 16.3.x, and 16.4.x. It was fixed in 16.0.1, 16.1.2, 16.2.1, 16.3.3, and 16.4.2."
    },
    {
      "lang": "es",
      "value": "Aplicaciones \"react\" que renderizaban a HTML mediante la API APIReactDOMServer no escapaban nombres de atributo proporcionados por el usuario a la hora de renderizar. Dicha falta de escape podría provocar una vulnerabilidad de Cross-Site Scripting (XSS). Este problema afectaba a pequeñas distribuciones: las versiones 16.0.x, 16.1.x, 16.2.x, 16.3.x y 16.4.x. Se solucionó en las versiones 16.0.1, 16.1.2, 16.2.1, 16.3.3 y 16.4.2."
    }
  ],
  "lastModified": "2026-06-17T02:01:41.990",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F2DBC72-D3BB-4F2E-8C4E-78338879F785",
              "versionEndExcluding": "16.0.1",
              "versionStartIncluding": "16.0.0"
            },
            {
              "criteria": "cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFDC1FE0-32FA-4087-BAC9-8BE468C2C890",
              "versionEndExcluding": "16.1.2",
              "versionStartIncluding": "16.1.0"
            },
            {
              "criteria": "cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "68B83811-5DEF-4C8D-A472-A2AB9B25AAB7",
              "versionEndExcluding": "16.2.1",
              "versionStartIncluding": "16.2.0"
            },
            {
              "criteria": "cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13B2835B-E9DB-49B7-9C1D-EFF8EDE1C367",
              "versionEndExcluding": "16.3.3",
              "versionStartIncluding": "16.3.0"
            },
            {
              "criteria": "cpe:2.3:a:facebook:react:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AFEFCB3B-A978-457C-A26E-D1A818DE878D",
              "versionEndExcluding": "16.4.2",
              "versionStartIncluding": "16.4.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-assign@fb.com"
}