CVE-2014-0014
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
15/02/2018
Last modified:
07/11/2023
Description
Ember.js 1.0.x before 1.0.1, 1.1.x before 1.1.3, 1.2.x before 1.2.1, 1.3.x before 1.3.1, and 1.4.x before 1.4.0-beta.2 allows remote attackers to conduct cross-site scripting (XSS) attacks by leveraging an application using the "{{group}}" Helper and a crafted payload.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
3.50
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:emberjs:ember.js:1.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:emberjs:ember.js:1.0.0:pre.2:*:*:*:*:*:* | ||
| cpe:2.3:a:emberjs:ember.js:1.0.0:pre.3:*:*:*:*:*:* | ||
| cpe:2.3:a:emberjs:ember.js:1.0.0:pre.4:*:*:*:*:*:* | ||
| cpe:2.3:a:emberjs:ember.js:1.0.0:rc.1:*:*:*:*:*:* | ||
| cpe:2.3:a:emberjs:ember.js:1.0.0:rc.1.1:*:*:*:*:*:* | ||
| cpe:2.3:a:emberjs:ember.js:1.0.0:rc.2:*:*:*:*:*:* | ||
| cpe:2.3:a:emberjs:ember.js:1.0.0:rc.2.1:*:*:*:*:*:* | ||
| cpe:2.3:a:emberjs:ember.js:1.0.0:rc.3:*:*:*:*:*:* | ||
| cpe:2.3:a:emberjs:ember.js:1.0.0:rc.3.1:*:*:*:*:*:* | ||
| cpe:2.3:a:emberjs:ember.js:1.0.0:rc.4:*:*:*:*:*:* | ||
| cpe:2.3:a:emberjs:ember.js:1.0.0:rc.4.1:*:*:*:*:*:* | ||
| cpe:2.3:a:emberjs:ember.js:1.0.0:rc.5:*:*:*:*:*:* | ||
| cpe:2.3:a:emberjs:ember.js:1.0.0:rc.5.1:*:*:*:*:*:* | ||
| cpe:2.3:a:emberjs:ember.js:1.0.0:rc.6:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



