Описание
Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7.
A flaw was found in Material for MkDocs. A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the search suggestion feature. A remote attacker could exploit this by crafting a malicious URL with a specially designed query parameter. After user interaction, this could lead to the execution of arbitrary JavaScript code in the context of the documentation site, potentially resulting in information disclosure or other client-side attacks.
Отчет
This Moderate DOM-based cross-site scripting flaw in Material for MkDocs requires user interaction with a specially crafted URL. The vulnerability affects an optional search suggestion feature, which limits its immediate impact on typical Red Hat deployments where this feature may not be enabled by default.
Меры по смягчению последствий
To mitigate this issue, disable the optional search.suggest feature in Material for MkDocs if it is not required for your deployment. Consult the Material for MkDocs documentation for specific configuration instructions on how to disable this feature. Disabling this feature may impact the search functionality of your documentation site.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Certification Program for Red Hat Enterprise Linux 9 | redhat-certification-cnf | Fix deferred | ||
| Red Hat Developer Hub | rhdh/rhdh-hub-rhel9 | Fix deferred | ||
| Red Hat Hardened Images | grafana12.4 | Not affected | ||
| Red Hat Hardened Images | grafana13.1 | Not affected | ||
| Red Hat Hardened Images | trivy | Not affected | ||
| Red Hat OpenShift Container Platform 4 | openshift4/ose-olm-catalogd-rhel9 | Fix deferred | ||
| Self-service automation portal 2 | ansible-automation-platform/bootc-automation-portal-rhel9 | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
5.4 Medium
CVSS3
Связанные уязвимости
Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7.
Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7.
Material for MkDocs is a powerful documentation framework built on top ...
EPSS
5.4 Medium
CVSS3