npm package
vis-timeline
pkg:npm/vis-timeline
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2020-28487 | — | < 7.4.4 | 7.4.4 | Jan 22, 2021 | This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application. |
- CVE-2020-28487Jan 22, 2021affected < 7.4.4fixed 7.4.4
This affects the package vis-timeline before 7.4.4. An attacker with the ability to control the items of a Timeline element can inject additional script code into the generated application.