Junglewise Threat Intelligence

Ember.js cross-site scripting vulnerability

Severity: info · Published 2017-10-24

Executive brief

Ember.js, a popular JavaScript framework for building web applications, contained a cross-site scripting (XSS) vulnerability that could allow attackers to inject malicious scripts into web pages. This vulnerability affects multiple versions of the framework and could enable attackers to steal user data, hijack sessions, or perform unauthorized actions on behalf of users. The advisory has been withdrawn as a duplicate, but the underlying XSS flaw existed across numerous versions from 1.8 through 2.2.

Technical details

A cross-site scripting (XSS) vulnerability exists in Ember.js that allows remote attackers to inject arbitrary web script or HTML. The vulnerability affects a wide range of versions: 1.8.x through 1.10.x, 1.11.x before 1.11.4, 1.12.x before 1.12.2, 1.13.x before 1.13.12, 2.0.x before 2.0.3, 2.1.x before 2.1.2, and 2.2.x before 2.2.1. The attack requires network access to an application using a vulnerable version of Ember.js. Successful exploitation allows injection of arbitrary web script or HTML, which could lead to session hijacking, data theft, or malware distribution. Patches are available in the fixed versions listed above.

Affected products

  • Ember Ember.js 1.8.0 through 1.10.x, 1.11.x before 1.11.4, 1.12.x before 1.12.2, 1.13.x before 1.13.12, 2.0.x before 2.0.3, 2.1.x before 2.1.2, 2.2.x before 2.2.1

Timeline

  • 2017-10-24: disclosed
  • 2020-06-17: other: Advisory withdrawn as accidental duplicate publish