Vulnerability Description
This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Visjs | Vis-Timeline | < 7.4.4 |
Related Weaknesses (CWE)
References
- https://github.com/visjs/vis-timeline/issues/838Issue TrackingThird Party Advisory
- https://github.com/visjs/vis-timeline/pull/840PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBVISJS-1063502ExploitPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1063501ExploitPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-VISTIMELINE-1063500ExploitPatchThird Party Advisory
- https://github.com/visjs/vis-timeline/issues/838Issue TrackingThird Party Advisory
- https://github.com/visjs/vis-timeline/pull/840PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBVISJS-1063502ExploitPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1063501ExploitPatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-VISTIMELINE-1063500ExploitPatchThird Party Advisory
FAQ
What is CVE-2020-28487?
CVE-2020-28487 is a vulnerability with a CVSS score of 6.8 (MEDIUM). This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.
How severe is CVE-2020-28487?
CVE-2020-28487 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-28487?
Check the references section above for vendor advisories and patch information. Affected products include: Visjs Vis-Timeline.