equinor / mad-expo-core

MIT License
0 stars 0 forks source link

ServiceMessage: Code security issue #133

Open HavardNot opened 1 year ago

HavardNot commented 1 year ago

Snyk reports a medium code security issue in Service Message:

Unsanitized input from a React useState value flows [:17, :60, :63, :64, :97, :99, :99] into url [:99], where it is used as an URL to redirect the user. This may result in an Open Redirect vulnerability.

tormodAase commented 1 month ago

Leaving this issue open.

This package is getting phased out, and we do not plan to make any improvements unless they are critical for the remaining apps.

Security is always important 💯