Описание
DOM-based XSS in gmail-js
Affected versions of gmail-js are vulnerable to cross-site scripting in the tools.parse_response, helper.get.visible_emails_post, and helper.get.email_data_post functions, which pass user input directly into the Function constructor.
Recommendation
Update to version 0.6.5 or later.
Пакеты
Наименование
gmail-js
npm
Затронутые версииВерсия исправления
<= 0.6.4
0.6.5
CVE ID
Дефекты
CWE-79
Связанные уязвимости
CVE ID
Дефекты
CWE-79