Highcharts JS is a JavaScript charting library based on SVG. In Highcharts versions 8 and earlier, the chart options structure was not systematically filtered for XSS vectors. The potential impact was that content from untrusted sources could execute code in the end user's browser. The vulnerability is patched in version 9. As a workaround, implementers who are not able to upgrade may apply DOMPurify recursively to the options structure to filter out malicious markup.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2021-05-05T15:30:18
Updated: 2024-08-03T22:11:05.477Z
Reserved: 2021-03-30T00:00:00
Link: CVE-2021-29489
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-05-05T16:15:08.023
Modified: 2024-11-21T06:01:14.670
Link: CVE-2021-29489
Redhat
No data.