Advisory Database
  • Advisories
  • Dependency Scanning
  1. gem
  2. ›
  3. mapbox-rails
  4. ›
  5. OSVDB-129854

OSVDB-129854: Content Injection via TileJSON attribute

October 24, 2015

If you use L.mapbox.map or L.mapbox.tileLayer to load untrusted TileJSON content from a non-Mapbox URL, it is possible for a malicious user with control over the TileJSON content to inject script content into the attribution value of the TileJSON which will be executed in the context of the page using Mapbox.js.

Code Behaviors & Features

Detect and mitigate OSVDB-129854 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions

Solution

There is no solution for this vulnerability at the moment.

Source file

gem/mapbox-rails/OSVDB-129854.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:08 +0000.