Description
Mapbox.js versions 1.x prior to 1.6.6 and 2.x prior to 2.2.4 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON name and map share control
Remediation
References
https://hackerone.com/reports/99245
https://nodesecurity.io/advisories/74
Related Vulnerabilities
CVE-2022-25301 Vulnerability in npm package jsgui-lang-essentials
CVE-2023-49486 Vulnerability in maven package com.jfinal:jfinal
CVE-2021-23396 Vulnerability in npm package lutils
CVE-2021-41269 Vulnerability in maven package com.cronutils:cron-utils
CVE-2020-25640 Vulnerability in maven package org.jboss.genericjms:generic-jms-ra-jar