Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-1000427

Опубликовано: 02 янв. 2018
Источник: debian

Описание

marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-markedfixed0.3.9+dfsg-1package

Примечания

  • https://github.com/chjj/marked/commit/cd2f6f5b7091154c5526e79b5f3bfb4d15995a51

  • nodejs not covered by security support

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 8 лет назад

marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.

CVSS3: 6.1
nvd
около 8 лет назад

marked version 0.3.6 and earlier is vulnerable to an XSS attack in the data: URI parser.

CVSS3: 6.1
github
около 8 лет назад

Marked vulnerable to XSS from data URIs