Description
Versions of google-closure-library prior to 20190301.0.0 are vulnerable to Cross-Site Scripting. The safedomtreeprocessor.processToString() function improperly processed empty elements, which could allow attackers to execute arbitrary JavaScript through Mutation Cross-Site Scripting.
Recommendation
Update the google-closure-library package to the latest compatible version. Followings are version details:
- Affected version(s): < 20190301.0.0
- Patched version(s): 20190301.0.0
References
Related Issues
- Cross-Site Scripting in react-marked-markdown - Vulnerability
- CKEditor cross-site scripting vulnerability in AJAX sample - CVE-2023-4771
- vue-i18n has cross-site scripting vulnerability with prototype pollution - CVE-2024-52809
- Stimulsoft Dashboard.JS Cross Site Scripting vulnerability - CVE-2024-24396
You might also like:
- Tags:
- npm
- google-closure-library
Anything's wrong? Let us know Last updated on January 09, 2023


