{"id":"GHSA-mp78-r56v-45qc","summary":"ember-source vulnerable to Cross-site Scripting","details":"Cross-site scripting (XSS) vulnerability in Ember.js 1.10.x before 1.10.1 and 1.11.x before 1.11.2.","aliases":["CVE-2015-1866"],"modified":"2023-11-01T04:46:00.162637Z","published":"2018-08-28T22:34:31Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:46:40Z","nvd_published_at":null,"cwe_ids":["CWE-79"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-1866"},{"type":"WEB","url":"https://emberjs.com/blog/2015/04/14/security-and-bugfix-releases-ember-1-10-1-1-11-2-1-11-3.html"},{"type":"PACKAGE","url":"https://github.com/Acidburn0zzz/ember.js"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ember-source/CVE-2015-1866.yml"},{"type":"WEB","url":"https://groups.google.com/forum/#!topic/ember-security/nbntfs2EbRU"},{"type":"WEB","url":"https://web.archive.org/web/20200228155301/http://www.securityfocus.com/bid/74185"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2015/04/14/11"}],"affected":[{"package":{"name":"ember-source","ecosystem":"RubyGems","purl":"pkg:gem/ember-source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.10.0"},{"fixed":"1.10.1"}]}],"versions":["1.10.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/08/GHSA-mp78-r56v-45qc/GHSA-mp78-r56v-45qc.json"}},{"package":{"name":"ember-source","ecosystem":"RubyGems","purl":"pkg:gem/ember-source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.11.0"},{"fixed":"1.11.2"}]}],"versions":["1.11.0","1.11.0.1","1.11.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/08/GHSA-mp78-r56v-45qc/GHSA-mp78-r56v-45qc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}