
We found results for “”
WS-2017-3755
Good to know:

Date: August 24, 2017
In google/closure-library, v20160106 to 20160208 there is a potential XSS vulnerability due to unsanitized URLs that attackers can use to inject commands.
Language: Java
Severity Score
Severity Score
Weakness Type (CWE)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE-79Top Fix

Upgrade Version
Upgrade to version slub/slub-web-kartenforum - dev-dev-integrate-mosaic-maps;slub/slub-web-kartenforum - v3.0.0;slub/slub-web-kartenforum - dev-develop-fixes;slub/slub-web-kartenforum - dev-dependabot/npm_and_yarn/Build/minimist-1.2.6;slub/slub-web-kartenforum - dev-dependabot/npm_and_yarn/Build/vk2/karma-6.3.14;slub/slub-web-kartenforum - dev-dependabot/npm_and_yarn/Build/vk2/follow-redirects-1.14.8;slub/slub-web-kartenforum - dev-dependabot/npm_and_yarn/Build/terser-5.14.2;org.webjars.npm:google-closure-library:20210808.0.0
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | NONE |
Availability (A): | NONE |