CVE-2023-3978 affecting package containerized-data-importer for versions less than 1.57.0-12
Details
Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.