Описание
Cross-site scripting in @atlaskit/editor-core
The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2019-20903
- https://atlaskit.atlassian.com/packages/editor/editor-core/changelog/113.1.5
- https://bitbucket.org/atlassian/atlaskit-mk-2/commits/ca88f616e4
- https://confluence.atlassian.com/pages/viewpage.action?pageId=1021244735
- https://www.npmjs.com/package/@atlaskit/editor-core
Пакеты
Наименование
@atlaskit/editor-core
npm
Затронутые версииВерсия исправления
Отсутствует
Связанные уязвимости
CVSS3: 5.4
nvd
больше 5 лет назад
The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.