Home

Description

tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /data/v3/?key.

PUBLISHED Reserved 2024-05-17 | Published 2024-05-22 | Updated 2025-02-13 | Assigner mitre

References

gist.github.com/SaleSlave/e23d49e7f8eb937784d15c2c2fc34fca

cve.org (CVE-2024-35627)

nvd.nist.gov (CVE-2024-35627)

Download JSON