GMS-2020-726: Cross-Site Scripting in google-closure-library
(updated )
Versions of google-closure-library
prior to 20190301.0.0 are vulnerable to Cross-Site Scripting. The safedomtreeprocessor.processToString()
function improperly processed empty elements, which could allow attackers to execute arbitrary JavaScript through Mutation Cross-Site Scripting.
Recommendation
Upgrade to version 20190301.0.0 or later.
References
Detect and mitigate GMS-2020-726 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →