Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p3rp-vmj9-gv6v

Опубликовано: 06 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Incorrect sanitisation function leads to XSS in mermaid

Impact

Malicious diagrams can contain javascript code that can be run at diagram readers machines.

Patches

The users should upgrade to version 8.13.8

Workarounds

You need to upgrade in order to avoid this issue.

Пакеты

Наименование

mermaid

npm
Затронутые версииВерсия исправления

< 8.13.8

8.13.8

EPSS

Процентиль: 65%
0.00493
Низкий

7.2 High

CVSS3

Дефекты

CWE-20
CWE-79

Связанные уязвимости

CVSS3: 7.2
ubuntu
около 4 лет назад

Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run javascript code at diagram readers' machines. Users should upgrade to version 8.13.8 to receive a patch. There are no known workarounds aside from upgrading.

CVSS3: 7.2
nvd
около 4 лет назад

Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run javascript code at diagram readers' machines. Users should upgrade to version 8.13.8 to receive a patch. There are no known workarounds aside from upgrading.

CVSS3: 7.2
debian
около 4 лет назад

Mermaid is a Javascript based diagramming and charting tool that uses ...

EPSS

Процентиль: 65%
0.00493
Низкий

7.2 High

CVSS3

Дефекты

CWE-20
CWE-79