Uploaded image for project: 'Spark'
  1. Spark
  2. SPARK-39740

vis-timeline @ 4.2.1 vulnerable to XSS attacks

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Minor
    • Resolution: Fixed
    • 3.2.1, 3.3.0
    • 3.5.0
    • Web UI
    • None

    Description

      Spark UI includes visjs/vis-timeline package@4.2.1, which is vulnerable to XSS attacks (Cross-site Scripting in vis-timeline · CVE-2020-28487 · GitHub Advisory Database). This version should be replaced with the next non-vulnerable issue - Release v7.4.4 · visjs/vis-timeline (github.com) or higher.

      Attachments

        Activity

          People

            shrprasa Shrikant Prasad
            ess-truveta Eugene Shinn (Truveta)
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: