
We found results for “”
CVE-2020-26296
Good to know:


Date: December 30, 2020
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an attacker could execute arbitrary javascript on a victim's machine. This is fixed in version 5.17.3
Language: JS
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix

Upgrade Version
Upgrade to version vega - 5.17.2;VegaHub - no_fix;org.webjars.bower:vega:3.0.0-beta.32;org.webjars.bower:vega:2.6.0;org.webjars.bower:vega:3.0.0-beta.25;org.webjars.bower:vega:3.0.0-rc3;org.webjars.bower:vega:no_fix;org.webjars.bower:vega:3.0.7;org.webjars.npm:vega-lib:no_fix;org.webjars.bowergithub.vega:vega:no_fix;org.webjars.bowergithub.vega:vega:5.3.4;org.webjars.npm:vega-expression:4.0.1;org.webjars.npm:vega:5.20.2
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | LOW |
User Interaction (UI): | REQUIRED |
Scope (S): | CHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | NONE |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | SINGLE |
Confidentiality (C): | NONE |
Integrity (I): | PARTIAL |
Availability (A): | NONE |
Additional information: |