Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-43827

Опубликовано: 14 дек. 2021
Источник: nvd
CVSS3: 4.3
CVSS2: 4
EPSS Низкий

Описание

discourse-footnote is a library providing footnotes for posts in Discourse. ### Impact When posting an inline footnote wrapped in <a> tags (e.g. <a>^[footnote]</a>, the resulting rendered HTML would include a nested <a>, which is stripped by Nokogiri because it is not valid. This then caused a javascript error on topic pages because we were looking for an <a> element inside the footnote reference span and getting its ID, and because it did not exist we got a null reference error in javascript. Users are advised to update to version 0.2. As a workaround editing offending posts from the rails console or the database console for self-hosters, or disabling the plugin in the admin panel can mitigate this issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:discourse:discourse_footnote:*:*:*:*:*:discourse:*:*
Версия до 0.2 (исключая)

EPSS

Процентиль: 51%
0.00281
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-755

EPSS

Процентиль: 51%
0.00281
Низкий

4.3 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-755