ember-source
RubyGems6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting ember-sourcepage 1 of 1
- CVE-2013-4170MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.0.0.rc6.12022-06-30
vulnerable: 1.0.0.rc6.0, 1.0.0.rc6
In general, Ember.js escapes or strips any user-supplied content before inserting it in strings that will be sent to innerHTML. However, the `tagName` property of an `Ember.View` was inserted into such a string without being sanitized. Thi…
- CVE-2014-0013MEDIUMCVSS 5.4✓ Fixed in 1.4.0-beta.22018-02-15
vulnerable: 1.4.0-beta.1
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application that contains templat…
- CVE-2014-0014MEDIUMCVSS 5.4✓ Fixed in 1.4.0-beta.22018-02-15
vulnerable: 1.4.0-beta.1
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application using the "{{group}}"…
- CVE-2014-0046NONECVSS 0.0✓ Fixed in 1.4.0.beta.62014-02-27
vulnerable: 1.4.0.beta.1, 1.4.0.beta.2, 1.4.0.beta.3, 1.4.0.beta.4, 1.4.0.beta.5
Cross-site scripting (XSS) vulnerability in the link-to helper in Ember.js 1.2.x before 1.2.2, 1.3.x before 1.3.2, and 1.4.x before 1.4.0-beta.6, when used in non-block form, allows remote attackers to inject arbitrary web script or HTML v…
- CVE-2015-1866MEDIUMCVSS 6.1EG 6.1✓ Fixed in 1.11.22017-09-20
vulnerable: 1.11.0, 1.11.0.1, 1.11.1
Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1.11.x before 1.11.2.
- CVE-2015-7565MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2.2.12017-04-13
vulnerable: 2.2.0
Cross-site scripting (XSS) vulnerability in Ember.js 1.8.x through 1.10.x, 1.11.x before 1.11.4, 1.12.x before 1.12.2, 1.13.x before 1.13.12, 2.0.x before 2.0.3, 2.1.x before 2.1.2, and 2.2.x before 2.2.1 allows remote attackers to inject …
Check whether ember-source is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for ember-source CVEs against the assets you own.
Start Free Scan →