laptop and a wrench

Bug

There is a stored cross-site scripting (XSS) vulnerability in ArcGIS API for JavaScript.

Last Published: October 18, 2021 ArcGIS API for JavaScript
Bug ID Number BUG-000133257
SubmittedAugust 21, 2020
Last ModifiedMay 31, 2023
Applies toArcGIS API for JavaScript
Version found4.16
Operating SystemWindows OS
Operating System Version10.0
Version Fixed3.37
StatusFixed

Workaround

The Portal for ArcGIS Security 2022 Update 1 Patch is now live on the support site. The URL is: https://support.esri.com/en/download/7948. This is a 3 version patch for 10.7.1, 10.8.1 and 10.9.1. Refer to the Issues Addressed section of the patch download page for details on which versions were affected and resolved for this defect.

Steps to Reproduce

Bug ID: BUG-000133257

Software:

  • ArcGIS API for JavaScript

Get help from ArcGIS experts

Contact technical support

Download the Esri Support App

Go to download options

Discover more on this topic