Description
Mapbox.js versions 1.x prior to 1.6.6 and 2.x prior to 2.2.4 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON name and map share control
Remediation
References
https://hackerone.com/reports/99245
https://nodesecurity.io/advisories/74
Related Vulnerabilities
CVE-2020-28480 Vulnerability in npm package jointjs
CVE-2021-32808 Vulnerability in maven package org.webjars.bowergithub.ckeditor:ckeditor4
CVE-2021-28162 Vulnerability in npm package @wiptheia/core
CVE-2022-31110 Vulnerability in npm package rsshub
CVE-2019-10349 Vulnerability in maven package org.jenkins-ci.plugins:depgraph-view