Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-28245

Опубликовано: 25 мар. 2024
Источник: debian

Описание

KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\includegraphics` that runs arbitrary JavaScript, or generate invalid HTML. Upgrade to KaTeX v0.16.10 to remove this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-katexfixed0.16.10+~cs6.1.0-1package
node-katexno-dsabookwormpackage
node-katexno-dsabullseyepackage

Примечания

  • https://github.com/KaTeX/KaTeX/security/advisories/GHSA-f98w-7cxr-ff2h

  • https://github.com/KaTeX/KaTeX/commit/c5897fcd1f73da9612a53e6b5544f1d776e17770 (v0.16.10)

Связанные уязвимости

CVSS3: 6.3
ubuntu
почти 2 года назад

KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\includegraphics` that runs arbitrary JavaScript, or generate invalid HTML. Upgrade to KaTeX v0.16.10 to remove this vulnerability.

CVSS3: 6.3
nvd
почти 2 года назад

KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\includegraphics` that runs arbitrary JavaScript, or generate invalid HTML. Upgrade to KaTeX v0.16.10 to remove this vulnerability.

CVSS3: 6.3
github
почти 2 года назад

KaTeX's `\includegraphics` does not escape filename