CesiumGS / CesiumGS/cesium

CVE-2023-48094 - XSS Vulnerability

Open
#11,642 3 comments 1 reaction 0 assignees View on GitHub
priority - high type - bug
Dominant language
JavaScript
Stars
15.7k
Forks
3.9k
Avg merge
4d 6h
Merged PRs (30d)
34

Description

As of last night, Cesium is now being flagged by Dependabot.

> A cross-site scripting (XSS) vulnerability in CesiumJS v1.111 allows attackers to execute arbitrary code in the context of the victim's browser via sending a crafted payload to /container_files/public_html/doc/index.html.

![image](https://github.com/CesiumGS/cesium/assets/20321959/1049146e-90d2-45b0-ab76-f4db55a61c50)

Contributor guide

Open the contributing guide

Research direction

Start with the Dependabot alert and the reported path /container_files/public_html/doc/index.html, then inspect the repository's handling of that document and the CVE-2023-48094 report. Done means the reported XSS exposure is addressed and the relevant security behavior is verified, but the issue does not specify a remediation or test location.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.