Replies: 1 comment 1 reply
-
I think this was fixed by #535 in https://github.com/maptiler/tileserver-gl/releases/tag/v4.4.2 If I test with my own server running v4.11.0 it has no effect Are you sure your test wasn't running 4.4.1 instead of 4.4.10? Either way, this should be fixed in the current release. _ |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello,
Found XSS vulnerability in TileServer GL (Vector data url)
Tested on 4.4.10
http://address:8089/data/v3/?key=%27-alert(1)-%27
and 3.1.1
http://address:8083/data/malaysia-vector/?key='-alert(1)-'
Do you already know about it ?
CVE-2024-35627
Affected version <=4.4.10
Its recommended to update to latest version
Beta Was this translation helpful? Give feedback.
All reactions