Jan. 13, 2023, 7:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

Gatsby is a free and open source framework based on React that helps developers build websites and apps. The gatsby-transformer-remark plugin prior to versions 5.25.1 and 6.3.2 passes input through to the `gray-matter` npm package, which is vulnerable to JavaScript injection in its default configuration, unless input is sanitized. The vulnerability is present in gatsby-transformer-remark when passing input in data mode (querying MarkdownRemark nodes via GraphQL). Injected JavaScript executes in the context of the build server. To exploit this vulnerability …

apps build configuration context cve data default developers exploit framework free graphql injection input javascript javascript injection matter mode nodes npm npm package open source package plugin react server vulnerability vulnerable websites

Senior Associate, Cybersecurity Operations

@ Ares Management Corporation | Los Angeles, CA - CULVER CITY

Senior DevSecOps Engineer

@ Peraton | Fort Gordon, GA, United States

Senior DevSecOps Engineer

@ Diverto | Zagreb, Croatia

Lead DevSecOps Engineer

@ DTCC | Tampa, FL, United States

Incident Responder (Fraud Threat Management)

@ Scotiabank | Toronto, ON, CA, M5H1H1

Penetration Tester, Expert (Federal agency) - Tysons, VA - Full Time

@ iSoftTek Solutions | Tysons, Virginia, United States