GMS-2017-122: XSS
When text/javascript responses are received from cross-origin ajax requests not containing the option dataType
, the result is executed in jQuery.globalEval
potentially allowing an attacker to execute arbitrary code on the origin.
Detect and mitigate GMS-2017-122 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →