Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-43861

Опубликовано: 30 дек. 2021
Источник: nvd
CVSS3: 7.2
CVSS3: 5.4
CVSS2: 3.5
EPSS Низкий

Описание

Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run javascript code at diagram readers' machines. Users should upgrade to version 8.13.8 to receive a patch. There are no known workarounds aside from upgrading.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mermaid_project:mermaid:*:*:*:*:*:node.js:*:*
Версия до 8.13.8 (исключая)

EPSS

Процентиль: 61%
0.00411
Низкий

7.2 High

CVSS3

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-20
NVD-CWE-Other

Связанные уязвимости

CVSS3: 7.2
ubuntu
около 4 лет назад

Mermaid is a Javascript based diagramming and charting tool that uses Markdown-inspired text definitions and a renderer to create and modify complex diagrams. Prior to version 8.13.8, malicious diagrams can run javascript code at diagram readers' machines. Users should upgrade to version 8.13.8 to receive a patch. There are no known workarounds aside from upgrading.

CVSS3: 7.2
debian
около 4 лет назад

Mermaid is a Javascript based diagramming and charting tool that uses ...

CVSS3: 7.2
github
около 4 лет назад

Incorrect sanitisation function leads to `XSS` in mermaid

EPSS

Процентиль: 61%
0.00411
Низкий

7.2 High

CVSS3

5.4 Medium

CVSS3

3.5 Low

CVSS2

Дефекты

CWE-20
NVD-CWE-Other