GHSA-r9q4-w3fm-wrm2

Suggest an improvement
Source
https://github.com/advisories/GHSA-r9q4-w3fm-wrm2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-r9q4-w3fm-wrm2/GHSA-r9q4-w3fm-wrm2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-r9q4-w3fm-wrm2
Published
2020-09-02T21:21:43Z
Modified
2021-09-27T21:01:47Z
Summary
Cross-Site Scripting in google-closure-library
Details

Versions of google-closure-library prior to 20190301.0.0 are vulnerable to Cross-Site Scripting. The safedomtreeprocessor.processToString() function improperly processed empty elements, which could allow attackers to execute arbitrary JavaScript through Mutation Cross-Site Scripting.

Recommendation

Upgrade to version 20190301.0.0 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:39:08Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / google-closure-library

Package

Name
google-closure-library
View open source insights on deps.dev
Purl
pkg:npm/google-closure-library

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20190301.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-r9q4-w3fm-wrm2/GHSA-r9q4-w3fm-wrm2.json"