GHSA-mp78-r56v-45qc
Dashboard / Vulnerabilities / GHSA-mp78-r56v-45qc
Summary: ember-source vulnerable to Cross-site Scripting
Details: Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1.11.x before 1.11.2.
References: https://nvd.nist.gov/vuln/detail/CVE-2015-1866, https://emberjs.com/blog/2015/04/14/security-and-bugfix-releases-ember-1-10-1-1-11-2-1-11-3.html, https://github.com/Acidburn0zzz/ember.js, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ember-source/CVE-2015-1866.yml, https://groups.google.com/forum/#!topic/ember-security/nbntfs2EbRU, https://web.archive.org/web/20200228155301/http://www.securityfocus.com/bid/74185, http://www.openwall.com/lists/oss-security/2015/04/14/11
Affected packages
Package
Name: ember-source
Purl: pkg:gem/ember-source
Affected ranges
Type: ECOSYSTEM
Events:
