icon

We found results for “

CVE-2020-26296

Good to know:

icon
icon

Date: December 30, 2020

Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an attacker could execute arbitrary javascript on a victim's machine. This is fixed in version 5.17.3

Language: JS

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version vega - 5.17.2;VegaHub - no_fix;org.webjars.bower:vega:3.0.0-beta.32;org.webjars.bower:vega:2.6.0;org.webjars.bower:vega:3.0.0-beta.25;org.webjars.bower:vega:3.0.0-rc3;org.webjars.bower:vega:no_fix;org.webjars.bower:vega:3.0.7;org.webjars.npm:vega-lib:no_fix;org.webjars.bowergithub.vega:vega:no_fix;org.webjars.bowergithub.vega:vega:5.3.4;org.webjars.npm:vega-expression:4.0.1;org.webjars.npm:vega:5.20.2

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): NONE

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): MEDIUM
Authentication (AU): SINGLE
Confidentiality (C): NONE
Integrity (I): PARTIAL
Availability (A): NONE
Additional information:

Do you need more information?

Contact Us