Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x52f-h5g4-8qv5

Опубликовано: 26 дек. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Marp Core allows XSS by improper neutralization of HTML sanitization

Marp Core (@marp-team/marp-core) from v3.0.2 to v3.9.0 and v4.0.0, are vulnerable to cross-site scripting (XSS) due to improper neutralization of HTML sanitization.

Impact

Marp Core includes an HTML sanitizer with allowlist support. In the affected versions, the built-in allowlist is enabled by default. When the allowlist is active, if insufficient HTML comments are included, the sanitizer may fail to properly sanitize HTML content and lead cross-site scripting (XSS).

Patches

Marp Core v3.9.1 and v4.0.1 have been patched to fix that.

Workarounds

If you are unable to update the package immediately, disable all HTML tags by setting html: false option in the Marp class constructor.

const marp = new Marp({ html: false })

References

Credits

Thanks to @Ry0taK for finding out this vulnerability.

Пакеты

Наименование

@marp-team/marp-core

npm
Затронутые версииВерсия исправления

>= 3.0.2, <= 3.9.0

3.9.1

Наименование

@marp-team/marp-core

npm
Затронутые версииВерсия исправления

= 4.0.0

4.0.1

EPSS

Процентиль: 21%
0.00067
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.3
nvd
около 1 года назад

@marp-team/marp-core is the core for Marp, which is the ecosystem to write your presentation with plain Markdown. Marp Core from v3.0.2 to v3.9.0 and v4.0.0, are vulnerable to cross-site scripting (XSS) due to improper neutralization of HTML sanitization. Marp Core v3.9.1 and v4.0.1 have been patched to fix that. If you are unable to update the package immediately, disable all HTML tags by setting html: false option in the Marp class constructor.

CVSS3: 5.3
fstec
около 4 лет назад

Уязвимость инструмента для создания презентаций на основе Markdown Marp Core, связанная с недостаточной защитой структуры веб-страницы, позволяющая нарушителю проводить межсайтовые сценарные атаки

EPSS

Процентиль: 21%
0.00067
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-79