CVE-2020-26296
HIGH
8,7
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: required
Scope: changed
Confidentiality: high
Integrity: high
Availability: none
LOW
3,5
Source: [email protected]
Access Vector: network
Access Complexity: medium
Authentication: single
Confidentiality: none
Integrity: partial
Availability: none
Description
AI Translation Available
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an attacker could execute arbitrary javascript on a victim's machine. This is fixed in version 5.17.3
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0041
Percentile
0,6th
Updated
EPSS Score Trend (Last 91 Days)
79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
StableCommon Consequences
Security Scopes Affected:
Access Control
Confidentiality
Integrity
Availability
Potential Impacts:
Bypass Protection Mechanism
Read Application Data
Execute Unauthorized Code Or Commands
Applicable Platforms
Technologies:
AI/ML, Web Based, Web Server
Application
Vega by Vega Project
Version Range Affected
To
5.17.3
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vega_project:vega:*:*:*:*:*:node.js:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://github.com/vega/vega/issues/3018
https://github.com/vega/vega/pull/3019
https://github.com/vega/vega/releases/tag/v5.17.3
https://github.com/vega/vega/security/advisories/GHSA-r2qc-w64x-6j54
https://www.npmjs.com/package/vega
https://github.com/vega/vega/issues/3018
https://github.com/vega/vega/pull/3019
https://github.com/vega/vega/releases/tag/v5.17.3
https://github.com/vega/vega/security/advisories/GHSA-r2qc-w64x-6j54
https://www.npmjs.com/package/vega