Advisory Database
  • Advisories
  • Dependency Scanning
  1. gem
  2. ›
  3. mapbox-rails
  4. ›
  5. OSVDB-132871

OSVDB-132871: Content Injection via TileJSON Name

January 12, 2016

If you use L.mapbox.map and L.mapbox.shareControl, it is possible for a malicious user with control over the TileJSON content to inject script content into the name value of the TileJSON. After clicking on the share control, the malicious code will execute in the context of the page using Mapbox.js.

Code Behaviors & Features

Detect and mitigate OSVDB-132871 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions

Solution

There is no solution for this vulnerability at the moment.

Source file

gem/mapbox-rails/OSVDB-132871.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:55 +0000.