CVE-2014-0046: ember-source Cross-site Scripting vulnerability
(updated )
Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x before 1.2.2, 1.3.x before 1.3.2, and 1.4.x before 1.4.0-beta.6, when used in non-block form, allows remote attackers to inject arbitrary web script or HTML via the title attribute.
References
- exchange.xforce.ibmcloud.com/vulnerabilities/91242
- github.com/advisories/GHSA-4q53-fqhc-cr46
- github.com/emberjs/ember.js
- github.com/emberjs/ember.js/commit/45ee8df2a0efc0afe233d6b9b17045782a2e6b2d
- github.com/emberjs/ember.js/commit/94b28b8773acf894c4d7d7fccf4411a706292436
- github.com/emberjs/ember.js/commit/ab3199e68e1d0fc3c8f7f453cd38c51fe02af90b
- github.com/rubysec/ruby-advisory-db/blob/master/gems/ember-source/CVE-2014-0046.yml
- groups.google.com/forum/
- nvd.nist.gov/vuln/detail/CVE-2014-0046
Code Behaviors & Features
Detect and mitigate CVE-2014-0046 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →