SAS® Risk Governance Framework 7.5 and SAS® Risk Governance Framework 7.6 contain a vulnerable version of Underscore.js and DOMPurify


Severity: High

Description: SAS Risk Governance Framework 7.5 and 7.6 contain Underscore 1.13.4 and DOMPurify 3.2.4, which contain the following vulnerabilities:

Potential Impact: The impact varies by the vulnerability. For additional information, see the CVE records.