Описание
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | 0.3.9+dfsg-1 |
| cosmic | not-affected | 0.3.9+dfsg-1 |
| devel | not-affected | 0.3.9+dfsg-1 |
| disco | not-affected | 0.3.9+dfsg-1 |
| eoan | not-affected | 0.3.9+dfsg-1 |
| esm-apps-legacy/xenial | needed | |
| esm-apps/bionic | not-affected | 0.3.9+dfsg-1 |
| esm-apps/focal | not-affected | 0.3.9+dfsg-1 |
| esm-apps/jammy | not-affected | 0.3.9+dfsg-1 |
Показывать по
10
Ссылки на источники
4.3 Medium
CVSS2
Связанные уязвимости
nvd
больше 11 лет назад
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Node.js allows remote attackers to conduct cross-site scripting (XSS) attacks via a vbscript tag in a link.
debian
больше 11 лет назад
Incomplete blacklist vulnerability in marked 0.3.2 and earlier for Nod ...
4.3 Medium
CVSS2