4.5.1
9 years ago
3 years ago
Known vulnerabilities in the org.webjars.bower:vega package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the How to fix Cross-site Scripting (XSS)? A fix was pushed into the | [0,) |
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) via the This makes it possible to specify any object with a How to fix Cross-site Scripting (XSS)? A fix was pushed into the | [0,) |
Affected versions of this package are vulnerable to Arbitrary Code Execution in the How to fix Arbitrary Code Execution? A fix was pushed into the | [0,) |
Affected versions of this package are vulnerable to Cross-site Scripting (XSS). Through a specially crafted Vega expression, an attacker could execute arbitrary javascript on a victim's machine. How to fix Cross-site Scripting (XSS)? There is no fixed version for | [0,) |
Affected versions of this package are vulnerable to Cross-site Scripting (XSS) in the expression parser and code generator. How to fix Cross-site Scripting (XSS)? There is no fixed version for | [0,) |
Affected versions of the package are vulnerable to Cross-site Scripting (XSS). There is no validation that the requested group is an existing group before calling its scale method and using the returned scale. How to fix Cross-site Scripting (XSS)? Upgrade | [,2.4.0) |