Description
Mapbox.js versions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON Name.
Remediation
References
https://hackerone.com/reports/54327
https://nodesecurity.io/advisories/49
Related Vulnerabilities
CVE-2021-26272 Vulnerability in npm package ckeditor4-dev
CVE-2022-23305 Vulnerability in maven package log4j:log4j
CVE-2022-25927 Vulnerability in maven package org.webjars.npm:ua-parser-js
CVE-2022-25645 Vulnerability in npm package dset
CVE-2020-36189 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind