Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-26237

Опубликовано: 24 нояб. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.9
CVSS3: 5.8

Описание

Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will result in prototype pollution of the base object's prototype during highlighting. If you allow users to insert custom HTML code blocks into your page/app via parsing Markdown code blocks (or similar) and do not filter the language names the user can provide you may be vulnerable. The pollution should just be harmless data but this can cause problems for applications not expecting these properties to exist and can result in strange behavior or application crashes, i.e. a potential DOS vector. If your website or application does not render user provided data it should be unaffected. Versions 9.18.2 and 10.1.2 and newer include fixes for this vulnerability. If you are using version 7 or 8 you are encouraged to upgrade to a newer release.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

9.18.5 ships the fix
esm-apps-legacy/xenial

released

8.2+ds-4ubuntu0.1~esm1
esm-apps/bionic

released

9.12.0+dfsg1-4ubuntu0.1~esm1
esm-apps/focal

released

9.12.0+dfsg1-5ubuntu0.1~esm1
esm-apps/jammy

not-affected

9.18.5 ships the fix
esm-apps/noble

not-affected

9.18.5 ships the fix
esm-apps/resolute

not-affected

9.18.5 ships the fix
esm-apps/xenial

released

8.2+ds-4ubuntu0.1~esm1
esm-infra-legacy/trusty

DNE

Показывать по

EPSS

Процентиль: 69%
0.01323
Низкий

4.9 Medium

CVSS2

5.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.8
redhat
почти 6 лет назад

Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will result in prototype pollution of the base object's prototype during highlighting. If you allow users to insert custom HTML code blocks into your page/app via parsing Markdown code blocks (or similar) and do not filter the language names the user can provide you may be vulnerable. The pollution should just be harmless data but this can cause problems for applications not expecting these properties to exist and can result in strange behavior or application crashes, i.e. a potential DOS vector. If your website or application does not render user provided data it should be unaffected. Versions 9.18.2 and 10.1.2 and newer include fixes for this vulnerability. If you are using version 7 or 8 you are encouraged to upgrade to a newer release.

CVSS3: 5.8
nvd
почти 6 лет назад

Highlight.js is a syntax highlighter written in JavaScript. Highlight.js versions before 9.18.2 and 10.1.2 are vulnerable to Prototype Pollution. A malicious HTML code block can be crafted that will result in prototype pollution of the base object's prototype during highlighting. If you allow users to insert custom HTML code blocks into your page/app via parsing Markdown code blocks (or similar) and do not filter the language names the user can provide you may be vulnerable. The pollution should just be harmless data but this can cause problems for applications not expecting these properties to exist and can result in strange behavior or application crashes, i.e. a potential DOS vector. If your website or application does not render user provided data it should be unaffected. Versions 9.18.2 and 10.1.2 and newer include fixes for this vulnerability. If you are using version 7 or 8 you are encouraged to upgrade to a newer release.

CVSS3: 5.8
debian
почти 6 лет назад

Highlight.js is a syntax highlighter written in JavaScript. Highlight. ...

CVSS3: 5.8
github
почти 6 лет назад

Prototype Pollution in highlight.js

CVSS3: 6.8
fstec
больше 5 лет назад

Уязвимость инструмента для подсветки синтаксиса Highlight.js, связанная с модификацией предполагаемых данных, позволяющая нарушителю нарушить целостность данных, а также вызвать отказ в обслуживании

EPSS

Процентиль: 69%
0.01323
Низкий

4.9 Medium

CVSS2

5.8 Medium

CVSS3