2.33.0
9 years ago
6 months ago
Known vulnerabilities in the org.webjars.bower:plotly.js package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.webjars.bower:plotly.js is a package that provides an easy and simple way to export package.json data. Affected versions of this package are vulnerable to Prototype Pollution via the How to fix Prototype Pollution? Upgrade | [,2.33.0) |
org.webjars.bower:plotly.js is a package that provides an easy and simple way to export package.json data. Affected versions of this package are vulnerable to Cross-site Scripting (XSS). How to fix Cross-site Scripting (XSS)? Upgrade | [,1.10.4)[1.11.0,1.16.0) |
Affected versions of the package allow attackers to trick an unsuspecting user into viewing a specially crafted plot on a site that uses
For more information, see Jared's post explaining the issue very well. How to fix Cross-site Scripting (XSS)? Upgrade to | [1.10.4,1.16.0) |
Affected versions of the package allowed the style attribute to be manipulated in the tag inside the embedded How to fix CSS Injection? Upgrade to | [,1.16.0) |