CVE-2020-7642: Cross-site Scripting
(updated )
lazysizes allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: data-vimeo
, data-vimeoparams
, data-youtube
and data-ytparams
References
Detect and mitigate CVE-2020-7642 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →