Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r9q4-w3fm-wrm2

Опубликовано: 02 сент. 2020
Источник: github
Github: Прошло ревью

Описание

Cross-Site Scripting in google-closure-library

Versions of google-closure-library prior to 20190301.0.0 are vulnerable to Cross-Site Scripting. The safedomtreeprocessor.processToString() function improperly processed empty elements, which could allow attackers to execute arbitrary JavaScript through Mutation Cross-Site Scripting.

Recommendation

Upgrade to version 20190301.0.0 or later.

Пакеты

Наименование

google-closure-library

npm
Затронутые версииВерсия исправления

< 20190301.0.0

20190301.0.0

Дефекты

CWE-79

Дефекты

CWE-79