Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2qc-w64x-6j54

Опубликовано: 30 дек. 2020
Источник: github
Github: Прошло ревью
CVSS3: 8.7

Описание

XSS in Vega

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an attacker could execute arbitrary javascript on a victim's machine.

This is fixed in version 5.17.3

Пакеты

Наименование

vega

npm
Затронутые версииВерсия исправления

< 5.17.3

5.17.3

EPSS

Процентиль: 61%
0.00407
Низкий

8.7 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.7
redhat
около 5 лет назад

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an attacker could execute arbitrary javascript on a victim's machine. This is fixed in version 5.17.3

CVSS3: 8.7
nvd
около 5 лет назад

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an attacker could execute arbitrary javascript on a victim's machine. This is fixed in version 5.17.3

CVSS3: 8.7
debian
около 5 лет назад

Vega is a visualization grammar, a declarative format for creating, sa ...

EPSS

Процентиль: 61%
0.00407
Низкий

8.7 High

CVSS3

Дефекты

CWE-79