chartkick.js
by Ankane
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-18841 | 0.00 | — | 0.01 | Nov 11, 2019 | Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution. | |||
| CVE-2019-12732 | 0.00 | — | 0.00 | Jun 6, 2019 | The Chartkick gem through 3.1.0 for Ruby allows XSS. |
- CVE-2019-18841Nov 11, 2019risk 0.00cvss —epss 0.01
Chartkick.js 3.1.0 through 3.1.3, as used in the Chartkick gem before 3.3.0 for Ruby, allows prototype pollution.
- CVE-2019-12732Jun 6, 2019risk 0.00cvss —epss 0.00
The Chartkick gem through 3.1.0 for Ruby allows XSS.