CVE-2020-28502: Code Injection
(updated )
Provided requests are sent synchronously (async=False
on xhr.open)
, malicious user input flowing into xhr.send
could result in arbitrary code being injected and run.
References
Detect and mitigate CVE-2020-28502 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →