{"id":"GHSA-r9q4-w3fm-wrm2","summary":"Cross-Site Scripting in google-closure-library","details":"Versions of `google-closure-library` prior to 20190301.0.0 are vulnerable to Cross-Site Scripting. The `safedomtreeprocessor.processToString()` function improperly processed empty elements, which could allow attackers to execute arbitrary JavaScript through Mutation Cross-Site Scripting.\n\n\n## Recommendation\n\nUpgrade to version 20190301.0.0 or later.","modified":"2021-09-27T21:01:47Z","published":"2020-09-02T21:21:43Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-08-31T18:39:08Z"},"references":[{"type":"WEB","url":"https://github.com/google/closure-library/commit/c79ab48e8e962fee57e68739c00e16b9934c0ffa#commitcomment-33294853"},{"type":"PACKAGE","url":"https://github.com/google/closure-library"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-GOOGLECLOSURELIBRARY-174519"},{"type":"WEB","url":"https://www.npmjs.com/advisories/878"}],"affected":[{"package":{"name":"google-closure-library","ecosystem":"npm","purl":"pkg:npm/google-closure-library"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"20190301.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-r9q4-w3fm-wrm2/GHSA-r9q4-w3fm-wrm2.json"}}],"schema_version":"1.9.0"}