Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE2OXAtNWg3NC13MzZm

Content Injection via TileJSON Name in mapbox.js

Versions 1.x prior to 1.6.6 and 2.x prior to 2.2.4 of mapbox.js are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios.

If L.mapbox.map or L.mapbox.shareControl are used in a manner that gives users control of the TileJSON content, it is possible to inject script content into the name value of the TileJSON. After clicking on the share control, the malicious code will execute in the context of the page using Mapbox.js.

Recommendation

Version 1.x: Update to version 1.6.6 or later.
Version 2.x: Update to version 2.2.4 or later.

Permalink: https://github.com/advisories/GHSA-q69p-5h74-w36f
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE2OXAtNWg3NC13MzZm
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 6 years ago
Updated: over 1 year ago


CVSS Score: 6.1
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Identifiers: GHSA-q69p-5h74-w36f, CVE-2017-1000043
References: Blast Radius: 27.1

Affected Packages

rubygems:mapbox-rails
Dependent packages: 1
Dependent repositories: 87
Downloads: 179,335 total
Affected Version Ranges: >= 2.0.0, < 2.2.4, >= 1.0.0, < 1.6.6
Fixed in: 2.2.4, 1.6.6
All affected versions: 1.0.2, 1.0.3, 1.6.1
All unaffected versions: 2.3.0
npm:mapbox.js
Dependent packages: 45
Dependent repositories: 318
Downloads: 26,148 last month
Affected Version Ranges: >= 2.0.0, < 2.2.4, < 1.6.6
Fixed in: 2.2.4, 1.6.6
All affected versions: 0.1.0, 0.3.0, 0.6.3, 0.6.4, 0.6.5, 0.6.6, 0.6.7, 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.1.0, 1.2.0, 1.3.0, 1.3.1, 1.4.0, 1.4.1, 1.4.2, 1.5.0, 1.5.1, 1.5.2, 1.6.0, 1.6.1, 1.6.2, 1.6.3, 1.6.4, 1.6.5, 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.1.7, 2.1.8, 2.1.9, 2.2.0, 2.2.1, 2.2.2, 2.2.3
All unaffected versions: 1.6.6, 1.6.7, 2.2.4, 2.3.0, 2.4.0, 3.0.0, 3.0.1, 3.1.0, 3.1.1, 3.2.0, 3.2.1, 3.3.0, 3.3.1