GMS-2020-126: Cross-Site Scripting in bootstrap-vue
(updated )
Versions of bootstrap-vue
are vulnerable to Cross-Site Scripting. Due to insufficient input sanitization, components may be vulnerable to Cross-Site Scripting through the options
variable. This may lead to the execution of malicious JavaScript on the user’s browser.
References
Detect and mitigate GMS-2020-126 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →