Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-21535

Опубликовано: 15 окт. 2024
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.

A flaw was found in markdown-to-jsx. This vulnerability allows an attacker to execute arbitrary code via Cross-site scripting (XSS) through the src property by injecting a malicious iframe element into the markdown.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel8Not affected
Node HealthCheck Operatorworkload-availability/node-remediation-console-rhel8Will not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Not affected
Red Hat Developer Hubrhdh-operator-containerNot affected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Red Hat OpenShift Data Science (RHODS)rhods/odh-dashboard-rhel8Fix deferred
Red Hat OpenShift Data Science (RHODS)rhods/odh-operator-rhel8Not affected
Red Hat OpenShift Data Science (RHODS)rhods/odh-rhel8-operatorNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2318700markdown-to-jsx: Cross-site Scripting vulnerability in markdown-to-jsx

EPSS

Процентиль: 35%
0.00145
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 1 года назад

Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.

CVSS3: 6.1
nvd
больше 1 года назад

Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to Cross-site Scripting (XSS) via the src property due to improper input sanitization. An attacker can execute arbitrary code by injecting a malicious iframe element in the markdown.

CVSS3: 6.1
debian
больше 1 года назад

Versions of the package markdown-to-jsx before 7.4.0 are vulnerable to ...

CVSS3: 6.1
github
больше 1 года назад

Cross site scripting in markdown-to-jsx

EPSS

Процентиль: 35%
0.00145
Низкий

6.1 Medium

CVSS3