Mapbox.js versions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON Name.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| mapbox.js(npm) | 0 | 1.6.5 | N/A |
| mapbox.js(npm) | 2.0.0 | 2.1.7 | N/A |
| mapbox-rails(RubyGems) | 1.0.0 | 1.6.5 | N/A |
| mapbox-rails(RubyGems) | 2.0.0 | 2.1.7 | N/A |
CVSS Metrics